CVE-2026-10536
CriticalAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.009
- 57th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,123
- of 17,787 indexed, latest versions
- Container images
- 994
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,123 of 17,787 indexed charts deploy, on 994 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+33 more | 8.5.0-2ubuntu10.11, 8.14.1-2+e19, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3 | 776 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more | 8.21.0-r0, 8.22.0-r0 | 218 |
- OSV records
- ALPINE-CVE-2026-10536DEBIAN-CVE-2026-10536UBUNTU-CVE-2026-10536ECHO-0d6f-7fbe-c7fa
- Also known as
- USN-8525-1
Charts affected
1,123 by stars
Container images carrying it
994 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| gisaia/ | b83b3e067173 | curl | 8.22.0-r0 | 2 |
| gisaia/ | a35977a5bb7d | curl | 8.22.0-r0 | 2 |
| gisaia/ | 1a3cc43d822f | curl | 8.22.0-r0 | 2 |
| gjeanmart/ | 926264c8f2d1 | curl | no fix listed | 2 |
| gotenberg/ | 87c16b9f3642 | curl | no fix listed | 2 |
| gotenberg/ | f29984bd1e22 | curl | no fix listed | 2 |
| grafana/ | 2175aaa91c96 | curl | 8.22.0-r0 | 2 |
| grafana/ | 9e1e77ade304 | curl | 8.22.0-r0 | 2 |
| grafana/ | e932bd6ed0e0 | curl | 8.22.0-r0 | 2 |
| graviteeio/ | 05fd67a93056 | curl | no fix listed | 2 |
| graviteeio/ | 27374522cd04 | curl | no fix listed | 2 |
| infisical/ | 02082bf13163 | curl | no fix listed | 2 |
| jenkins/ | b470bcdc4ecd | curl | no fix listed | 2 |
| jenkins/ | c4098086090c | curl | no fix listed | 2 |
| jupyterhub/ | 69a7170eeeda | curl | 8.22.0-r0 | 2 |
| kurento/ | 03c0d34d0828 | curl | 8.5.0-2ubuntu10.11 | 2 |
| library/ | 04907bdd423b | curl | no fix listed | 2 |
| library/ | 5f5c8640aae0 | curl | 8.22.0-r0 | 2 |
| library/ | df7f1c2fb114 | curl | 8.22.0-r0 | 2 |
| library/ | 89729a95066a | curl | 8.5.0-2ubuntu10.11 | 2 |
| library/ | b8d940ca9376 | curl | no fix listed | 2 |
| library/ | 098862b1339f | curl | 8.5.0-2ubuntu10.11 | 2 |
| library/ | b97df9e0e1ee | curl | no fix listed | 2 |
| library/ | 6e23479198b9 | curl | no fix listed | 2 |
| library/ | 98f8ec75657d | curl | no fix listed | 2 |
| library/ | 9dd288848f44 | curl | no fix listed | 2 |
| library/ | 6e75aa8f767c | curl | no fix listed | 2 |
| library/ | eedf63967cdb | curl | no fix listed | 2 |
| library/ | f474a901faec | curl | no fix listed | 2 |
| library/ | 30bff39330d1 | curl | no fix listed | 2 |
| localstack/ | 4aef81c53168 | curl | no fix listed | 2 |
| louislam/ | 917318f9d7be | curl | no fix listed | 2 |
| louislam/ | 9aeb4e51d038 | curl | no fix listed | 2 |
| louislam/ | a8610b3b4c38 | curl | no fix listed | 2 |
| metabase/ | 9491ed11c901 | curl | 8.22.0-r0 | 2 |
| moby/ | 504731e577c2 | curl | 8.22.0-r0 | 2 |
| moreillon/ | c9f85db3baa5 | curl | no fix listed | 2 |
| moreillon/ | e1c9bfab5c16 | curl | no fix listed | 2 |
| moreillon/ | b067dbbbb6af | curl | no fix listed | 2 |
| nginxinc/ | cb92301e719d | curl | no fix listed | 2 |
| opencloudeu/ | 1691ad6612a3 | curl | no fix listed | 2 |
| opencloudeu/ | 27cb9b952f0d | curl | no fix listed | 2 |
| opencloudeu/ | 5b176baa3694 | curl | no fix listed | 2 |
| opencloudeu/ | 6e8b2df6c5a4 | curl | no fix listed | 2 |
| opencloudeu/ | 82f888a34440 | curl | no fix listed | 2 |
| opencloudeu/ | e0ac35a9576e | curl | no fix listed | 2 |
| opendatacube/ | 668cbb41473c | curl | 8.5.0-2ubuntu10.11 | 2 |
| openebs/ | 99f5116f5cb8 | curl | 8.22.0-r0 | 2 |
| polyaxon/ | eca6952b20e6 | curl | no fix listed | 2 |
| polyaxon/ | 024ff3fa775e | curl | no fix listed | 2 |