StackRadar

CVE-2026-10536

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,107
of 17,790 indexed, latest versions
Container images
975
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,107 of 17,790 indexed charts deploy, on 975 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+33 more8.5.0-2ubuntu10.11, 8.14.1-2+e19, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3765
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0210
OSV records
ALPINE-CVE-2026-10536DEBIAN-CVE-2026-10536UBUNTU-CVE-2026-10536ECHO-0d6f-7fbe-c7fa
Also known as
USN-8525-1

Charts affected

1,107 by stars
ChartLatestAffected imagesRadar Score
prismeai-appsprismeai0.7.11 of 4See more

prismeai-apps prismeai 0.7.1

1 of the 4 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,752
prismeai-coreprismeai1.12.11 of 7See more

prismeai-core prismeai 1.12.1

1 of the 7 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

3,271
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

5,234
web-chartpsb-ktcloudlab0.1.01 of 1See more

web-chart psb-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
web-chartpsg-ktcloudlab0.1.01 of 1See more

web-chart psg-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
nginx-chartpshs-nginx0.1.01 of 1See more

nginx-chart pshs-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
curl@7.88.1-10
no fix listed

Open the chart page →

12,652
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

11,400
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

11,400
open-terminalqaoruVerified publisher0.2.41 of 1See more

open-terminal qaoru 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/open-webui/open-terminal:0.13.0-slimdec44673c865
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,000
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

4,231
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

7,691
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

4,117
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

20,812
app-configradar-baseVerified publisher1.7.21 of 1See more

app-config radar-base 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.11

Open the chart page →

2,075
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.11

Open the chart page →

2,457
data-dashboard-backendradar-baseVerified publisher0.6.21 of 1See more

data-dashboard-backend radar-base 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.11

Open the chart page →

2,058
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
curl@8.18.0-1ubuntu2.1
8.18.0-1ubuntu2.3

Open the chart page →

3,221
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.11

Open the chart page →

2,322
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.11

Open the chart page →

2,893
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.11

Open the chart page →

2,504
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.11

Open the chart page →

3,057
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.11

Open the chart page →

2,571
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
curl@8.5.0-2ubuntu10.4
8.5.0-2ubuntu10.11

Open the chart page →

2,776
sqpreadyset-sqp-nightly0.1.0-nightly.202604302 of 3See more

sqp readyset-sqp-nightly 0.1.0-nightly.20260430

2 of the 3 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
readysettech/sqp:latest588f3507280e
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.11
readysettech/sqp-duckdb:latest67a83203ce60
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.11

Open the chart page →

3,514
redis-enforce-expireredis-enforce-expire1.0.01 of 1See more

redis-enforce-expire redis-enforce-expire 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
udhos/redis-enforce-expire:1.0.0615b6a7d742e
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,303
my-nginx-apprepo-for-helm-nginx-app0.1.01 of 1See more

my-nginx-app repo-for-helm-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,252
delugeretsamedocVerified publisher26.9.01 of 1See more

deluge retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
linuxserver/deluge:2.2.09505c64720af
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

782
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

6,562
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

3,753
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
curl@7.88.1-10+deb12u5
no fix listed
istio/examples-helloworld-v2:latest0a7f02b2c7c9
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

8,298
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

15,623
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

9,275
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

6,154
monitoringrocketchat-server0.0.171 of 9See more

monitoring rocketchat-server 0.0.17

1 of the 9 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

6,860
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

5,329
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

9,152
caddy-reverse-proxyromholdings0.10.11 of 1See more

caddy-reverse-proxy romholdings 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

846
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

66,542
devtron-operatorromholdings0.23.32 of 11See more

devtron-operator romholdings 0.23.3

2 of the 11 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
curl@8.5.0-2ubuntu10.10
8.5.0-2ubuntu10.11

Open the chart page →

31,447
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
rommapp/romm:5.2.03512f2ca4557
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

3,415
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

10,492
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

27,282
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

2,615
linkdingrubxkubeVerified publisher1.2.31 of 1See more

linkding rubxkube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.46.20c0a9a04c7eb
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,063
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,458
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.11

Open the chart page →

6,293
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

29,870
vaultwardenrubxkubeVerified publisher1.2.41 of 1See more

vaultwarden rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-10536.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,756

Container images carrying it

975 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.11
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.11
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
curl@8.19.0-r0
8.22.0-r0
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
curl@8.14.1-2+deb13u4
no fix listed
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
curl@8.17.0-r1
8.22.0-r0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
curl@8.14.1-2+deb13u4
no fix listed
1
quay.io/groundcover/tools:20260719b705e0cbe171
curl@1:8.14.1-2+deb13u3+e1
8.14.1-2+e19
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
curl@7.88.1-10+deb12u15
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
curl@7.88.1-10+deb12u14
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
curl@7.88.1-10+deb12u14
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
curl@7.88.1-10+deb12u15
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
curl@8.14.1-2+deb13u2
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
curl@8.5.0-2ubuntu10.10
8.5.0-2ubuntu10.11
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
curl@8.14.1-2+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
curl@8.14.1-2+deb13u4
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
curl@8.20.0-r0
8.22.0-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
curl@8.14.1-2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
curl@7.88.1-10+deb12u4
no fix listed
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
curl@8.17.0-r1
8.22.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.