StackRadar

CVE-2026-10536

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,107
of 17,790 indexed, latest versions
Container images
975
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,107 of 17,790 indexed charts deploy, on 975 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+33 more8.5.0-2ubuntu10.11, 8.14.1-2+e19, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3765
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0210
OSV records
ALPINE-CVE-2026-10536DEBIAN-CVE-2026-10536UBUNTU-CVE-2026-10536ECHO-0d6f-7fbe-c7fa
Also known as
USN-8525-1

Charts affected

1,107 by stars
ChartLatestAffected imagesRadar Score
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

13,197
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839

Container images carrying it

975 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
supabase/postgres:17.6.1.136f371b5f3f2ac
curl@8.19.0-r0
8.22.0-r0
1
supabase/realtime:v2.102.3aa1c92c0cf32
curl@7.88.1-10+deb12u14
no fix listed
1
supabase/realtime:v2.33.8d207e6e23ad3
curl@7.88.1-10+deb12u7
no fix listed
1
supabase/realtime:latestd3aa0c86c7b3
curl@8.14.1-2+deb13u4
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
curl@7.88.1-10+deb12u7
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
curl@7.88.1-10+deb12u15
no fix listed
1
supabase/studio:latest94a2a9d2906e
curl@7.88.1-10+deb12u15
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
curl@7.88.1-10+deb12u5
no fix listed
1
syncthing/syncthing:2.1.07c60eb0ec887
curl@8.17.0-r1
8.22.0-r0
1
sysnet4admin/colosseum-cms:loge74b43c7f492
curl@7.88.1-10+deb12u12
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
curl@7.88.1-10+deb12u12
no fix listed
1
tautulli/tautulli:latest670e68dd9efc
curl@8.14.1-2+deb13u4
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
curl@7.88.1-10+deb12u5
no fix listed
1
temporalio/admin-tools:1.28cfde8170c92f
curl@8.17.0-r1
8.22.0-r0
1
temporalio/auto-setup:1.29.7f14912b699cf
curl@8.19.0-r0
8.22.0-r0
1
tenureai/tenure:v1.0.285f5b222df9a5
curl@8.14.1-2+deb13u3+dhi3
no fix listed
1
theradius/loggia:0.463ba348546ec
curl@7.88.1-10+deb12u5
no fix listed
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
curl@8.14.1-2+deb13u2
no fix listed
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
curl@8.14.1-2+deb13u2
no fix listed
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
curl@8.14.1-2+deb13u4
no fix listed
1
thingsboard/tbmq-node:2.4.070661025dba5
curl@8.14.1-2+deb13u4
no fix listed
1
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
curl@8.14.1-2+deb13u2
no fix listed
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
curl@8.14.1-2+deb13u2
no fix listed
1
tombursch/kitchenowl-web:v0.7.8517f808eee66
curl@8.17.0-r1
8.22.0-r0
1
tomsquest/docker-radicale:3.6.1.0a594c624c5a6
curl@8.17.0-r1
8.22.0-r0
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
curl@7.88.1-10+deb12u8
no fix listed
1
twentycrm/twenty:v2.22.0e7d9948bf284
curl@8.19.0-r0
8.22.0-r0
1
udhos/eks-auto-pod-id-assoc:0.6.0196ef68af380
curl@8.19.0-r0
8.22.0-r0
1
udhos/k8s-mutating-admission-webhook:1.15.1e588db500edf
curl@8.19.0-r0
8.22.0-r0
1
udhos/redis-enforce-expire:1.0.0615b6a7d742e
curl@8.17.0-r1
8.22.0-r0
1
udhos/sqs-to-sns:2.0.15cf7979da82e1
curl@8.19.0-r0
8.22.0-r0
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
curl@7.88.1-10+deb12u12
no fix listed
1
vaultwarden/server:1.35.443498a94b22f
curl@8.14.1-2+deb13u2
no fix listed
1
vaultwarden/server:1.34.384fd8a47f58d
curl@7.88.1-10+deb12u12
no fix listed
1
vaultwarden/server:1.35.79a8eec71f4a5
curl@8.14.1-2+deb13u2
no fix listed
1
vaultwarden/server:1.36.0-alpined3531610b486
curl@8.17.0-r1
8.22.0-r0
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
curl@7.88.1-10+deb12u12
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
curl@7.88.1-10+deb12u1
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
curl@7.88.1-10+deb12u1
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
curl@7.88.1-10+deb12u1
no fix listed
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
curl@8.14.1-2+deb13u4
no fix listed
1
wallarm/api-gateway:0.2.0a3d4d2f780e8
curl@7.88.1-10+deb12u14
no fix listed
1
wallarm/gateway-controller:0.4.09c6ed23e2f0e
curl@8.14.1-2+deb13u3
no fix listed
1
wiktorn/overpass-api:latest9bb5f4a9b54c
curl@7.88.1-10+deb12u15
no fix listed
1
wsjbr/duplistatus:1.4.25e594f5f09f6
curl@8.20.0-r1
8.21.0-r0
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
curl@7.88.1-10+deb12u6
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
curl@7.88.1-10+deb12u6
no fix listed
1
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
curl@8.14.1-2+deb13u4
no fix listed
1
yetiplatform/yeti:2.9.09bcbe2650a14
curl@8.14.1-2+deb13u4
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.