CVE-2026-10536
CriticalAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.009
- 57th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,123
- of 17,787 indexed, latest versions
- Container images
- 994
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,123 of 17,787 indexed charts deploy, on 994 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+33 more | 8.5.0-2ubuntu10.11, 8.14.1-2+e19, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3 | 776 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more | 8.21.0-r0, 8.22.0-r0 | 218 |
- OSV records
- ALPINE-CVE-2026-10536DEBIAN-CVE-2026-10536UBUNTU-CVE-2026-10536ECHO-0d6f-7fbe-c7fa
- Also known as
- USN-8525-1
Charts affected
1,123 by stars
Container images carrying it
994 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| falcosecurity/ | 7df783d5269a | curl | no fix listed | 1 |
| felipecs8/ | 29e06c9c6385 | curl | no fix listed | 1 |
| filebrowser/ | dbac07403040 | curl | 8.22.0-r0 | 1 |
| firefart/ | 0d6249906d8c | curl | no fix listed | 1 |
| fireflyiii/ | ae69fdd95cde | curl | no fix listed | 1 |
| fiware/ | d551a13e8278 | curl | no fix listed | 1 |
| flanksource/ | 689687a7cf95 | curl | 8.5.0-2ubuntu10.11 | 1 |
| flashcatcloud/ | 42e6ab16472e | curl | 8.5.0-2ubuntu10.11 | 1 |
| fluent/ | a52221a2a3eb | curl | no fix listed | 1 |
| fluent/ | a941bdd5ca55 | curl | no fix listed | 1 |
| fluent/ | ca08b7d2df5b | curl | no fix listed | 1 |
| fluent/ | e76397ef3983 | curl | no fix listed | 1 |
| folioci/ | f0655a6a08fd | curl | 8.22.0-r0 | 1 |
| fosrl/ | 83a55f933b4d | curl | no fix listed | 1 |
| fosrl/ | c32ad797ab96 | curl | 8.22.0-r0 | 1 |
| freikin/ | 11826c67e4b1 | curl | no fix listed | 1 |
| galaxy/ | e50a890e24c9 | curl | no fix listed | 1 |
| geonode/ | 435cbc5f3f05 | curl | 8.21.0-r0 | 1 |
| getsentry/ | ba7bf9163219 | curl | no fix listed | 1 |
| ghostfolio/ | e3c6ab53e49b | curl | no fix listed | 1 |
| gitea/ | 7940221bcfc9 | curl | 8.22.0-r0 | 1 |
| gitea/ | b5c35d6bdbb9 | curl | 8.22.0-r0 | 1 |
| gitea/ | c2a169c5e998 | curl | 8.22.0-r0 | 1 |
| gitea/ | 7d13848af126 | curl | 8.22.0-r0 | 1 |
| glpi/ | 4b681082a79e | curl | no fix listed | 1 |
| gomods/ | 0f61d1e62359 | curl | 8.22.0-r0 | 1 |
| gomods/ | 97cc113b34b0 | curl | 8.22.0-r0 | 1 |
| google/ | f7d3e6d6d4f4 | curl | 8.22.0-r0 | 1 |
| gotenberg/ | 206a6c708fc6 | curl | no fix listed | 1 |
| gotenberg/ | 67097317623a | curl | no fix listed | 1 |
| gotenberg/ | a40f92d7419a | curl | no fix listed | 1 |
| gradiant/ | 332031245fce | curl | 8.5.0-2ubuntu10.11 | 1 |
| grafana/ | 0f86bada30d6 | curl | 8.22.0-r0 | 1 |
| grafana/ | 2d1f9ae67c17 | curl | 8.22.0-r0 | 1 |
| grafana/ | ba93c9d192e5 | curl | 8.22.0-r0 | 1 |
| graviteeio/ | 4140932887e0 | curl | 8.22.0-r0 | 1 |
| grpl/ | c00aafee6629 | curl | 8.5.0-2ubuntu10.11 | 1 |
| gulacedia/ | 67b467d961ca | curl | no fix listed | 1 |
| haohanyang/ | 54f2112602ee | curl | no fix listed | 1 |
| haohanyang/ | f4f8fe4e21f1 | curl | no fix listed | 1 |
| haproxytech/ | 7a3ef2dd8b5b | curl | 8.22.0-r0 | 1 |
| haproxytech/ | b9bffe2d0fd1 | curl | 8.22.0-r0 | 1 |
| haproxytech/ | d90f628d659e | curl | 8.22.0-r0 | 1 |
| hazegoodlife/ | 50f02d2d5d4d | curl | no fix listed | 1 |
| hazegoodlife/ | 8d4c63169e14 | curl | no fix listed | 1 |
| hazelcast/ | f086bf0ecb23 | curl | 8.22.0-r0 | 1 |
| healthchecks/ | aa08a61b0dcf | curl | no fix listed | 1 |
| heartexlabs/ | aa461572e8f9 | curl | 8.22.0-r0 | 1 |
| hecrom/ | bb0372939c19 | curl | no fix listed | 1 |
| helicone/ | 4a913936c97b | curl | no fix listed | 1 |