CVE-2026-10536
CriticalAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.009
- 57th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,123
- of 17,787 indexed, latest versions
- Container images
- 994
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,123 of 17,787 indexed charts deploy, on 994 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+33 more | 8.5.0-2ubuntu10.11, 8.14.1-2+e19, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3 | 776 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more | 8.21.0-r0, 8.22.0-r0 | 218 |
- OSV records
- ALPINE-CVE-2026-10536DEBIAN-CVE-2026-10536UBUNTU-CVE-2026-10536ECHO-0d6f-7fbe-c7fa
- Also known as
- USN-8525-1
Charts affected
1,123 by stars
Container images carrying it
994 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| qichenxu4pd/ | f3a8502bc21b | curl | no fix listed | 2 |
| quickwit/ | 363ff56ce456 | curl | no fix listed | 2 |
| rajnandan1/ | 30407afca731 | curl | no fix listed | 2 |
| requarks/ | 68f0d1848261 | curl | 8.22.0-r0 | 2 |
| syncthing/ | 775c4aac4862 | curl | 8.22.0-r0 | 2 |
| uffizzi/ | 0344805f267b | curl | no fix listed | 2 |
| vdiogov/ | 6945f84f0058 | curl | no fix listed | 2 |
| zabbix/ | 349b924472a7 | curl | 8.5.0-2ubuntu10.11 | 2 |
| ghcr.io/ | 82d0b161161d | curl | 8.5.0-2ubuntu10.11 | 2 |
| ghcr.io/ | a7805a8a60ff | curl | 8.22.0-r0 | 2 |
| ghcr.io/ | 7962759d99d7 | curl | no fix listed | 2 |
| ghcr.io/ | c80ae007ce2c | curl | no fix listed | 2 |
| ghcr.io/ | cd264d33efd4 | curl | no fix listed | 2 |
| ghcr.io/ | 612d76760b54 | curl | 8.21.0-r0 | 2 |
| ghcr.io/ | a1bc133af84e | curl | 8.21.0-r0 | 2 |
| ghcr.io/ | 3db8145349a3 | curl | no fix listed | 2 |
| ghcr.io/ | 95ee018cf558 | curl | no fix listed | 2 |
| ghcr.io/ | 4457b79b24cd | curl | no fix listed | 2 |
| quay.io/ | 5fc69e31c755 | curl | 8.5.0-2ubuntu10.11 | 2 |
| registry.gitlab.com/ | b1198ea741d1 | curl | 8.22.0-r0 | 2 |
| registry.gitlab.com/ | 9bdb1062d960 | curl | 8.22.0-r0 | 2 |
| 1dev/ | cd5b12fe5471 | curl | 8.5.0-2ubuntu10.11 | 1 |
| 48n6e/ | a6ed886fddfc | curl | no fix listed | 1 |
| aapjeisbaas/ | 6b261abc7fb0 | curl | no fix listed | 1 |
| aboogie/ | 9c41a4483ac8 | curl | no fix listed | 1 |
| adamzammit/ | f48962e1528c | curl | no fix listed | 1 |
| adorsys/ | 85be7a45a94c | curl | 8.5.0-2ubuntu10.11 | 1 |
| adorsys/ | eb49a2dcbbb8 | curl | 8.5.0-2ubuntu10.11 | 1 |
| agentarea/ | 9e15e16fa758 | curl | no fix listed | 1 |
| agentarea/ | d3c209a5d531 | curl | no fix listed | 1 |
| airbyte/ | 3b3a670af168 | curl | no fix listed | 1 |
| airbyte/ | 98d2c39d512e | curl | no fix listed | 1 |
| akaunting/ | 52811b36ec3a | curl | no fix listed | 1 |
| akeyless/ | 759e4289fae8 | curl | 8.5.0-2ubuntu10.11 | 1 |
| aktosecurity/ | 213aded7adc5 | curl | 8.5.0-2ubuntu10.11 | 1 |
| aktosecurity/ | 46ed5bcb04b2 | curl | 8.18.0-1ubuntu2.3 | 1 |
| aktosecurity/ | 5d4eab1c36b9 | curl | 8.18.0-1ubuntu2.3 | 1 |
| alazidis/ | 602d4f7f090c | curl | no fix listed | 1 |
| allegroai/ | 713ae38f7daf | curl | no fix listed | 1 |
| alpine/ | 905a068da431 | curl | 8.21.0-r0 | 1 |
| alpine/ | 44ef4942e171 | curl | 8.21.0-r0 | 1 |
| alpine/ | b7a12c5ddf26 | curl | 8.21.0-r0 | 1 |
| alpine/ | d870622d0040 | curl | 8.21.0-r0 | 1 |
| alpine/ | 1ee9df6316d4 | curl | 8.22.0-r0 | 1 |
| alpine/ | 862d86046bbc | curl | 8.22.0-r0 | 1 |
| alpine/ | c4a11ae9a1cb | curl | 8.22.0-r0 | 1 |
| andrewgaul/ | 7dc1d34174a5 | curl | 8.5.0-2ubuntu10.11 | 1 |
| antrea/ | ee9686bcefb8 | curl | no fix listed | 1 |
| anujdatar/ | 685df04a643b | curl | no fix listed | 1 |
| apache/ | 0305c26f19ed | curl | 8.5.0-2ubuntu10.11 | 1 |