StackRadar

CVE-2026-11856

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,708
of 17,787 indexed, latest versions
Container images
1,531
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,708 of 17,787 indexed charts deploy, on 1,531 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16+109 more7.35.0-1ubuntu2.20+esm22, 7.47.0-1ubuntu2.19+esm18, 7.58.0-2ubuntu3.24+esm11, 7.68.0-1ubuntu2.25+esm6+4 more1,313
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0218
OSV records
ALPINE-CVE-2026-11856DEBIAN-CVE-2026-11856UBUNTU-CVE-2026-11856ECHO-895d-0fcf-45bd
Also known as
USN-8651-1

Charts affected

1,708 by stars
ChartLatestAffected imagesRadar Score
ingress-nginxingress-nginx4.15.11 of 2See more

ingress-nginx ingress-nginx 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,548
jenkinsjenkinsciOfficialVerified publisher5.9.621 of 2See more

jenkins jenkinsci 5.9.62

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-jdk21c1e4c349365f
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,527
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,538
giteagiteaOfficialVerified publisher12.7.01 of 4See more

gitea gitea 12.7.0

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

8,842
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.26

Open the chart page →

6,597
artifact-hubartifact-hubVerified publisher1.23.01 of 7See more

artifact-hub artifact-hub 1.23.0

1 of the 7 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

10,782
jupyterhubjupyterhubOfficialVerified publisher4.4.23 of 7See more

jupyterhub jupyterhub 4.4.2

3 of the 7 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
curl@8.17.0-r1
8.22.0-r0
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
curl@7.88.1-10+deb12u15
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

7,909
mimir-distributedgrafana6.2.01 of 6See more

mimir-distributed grafana 6.2.0

1 of the 6 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

4,519
natsnatsVerified publisher2.14.61 of 3See more

nats nats 2.14.6

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
natsio/nats-box:0.19.7ffce8bd10338
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

2,315
metabasepmint932.27.61 of 1See more

metabase pmint93 2.27.6

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,640
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

30,167
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

11,372
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

5,309
kongkongOfficialVerified publisher3.4.11 of 2See more

kong kong 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/kong:3.92a8cf3b110cd
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12

Open the chart page →

1,174
openebsopenebsOfficialVerified publisher4.6.11 of 35See more

openebs openebs 4.6.1

1 of the 35 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
openebs/provisioner-localpv:4.6.099f5116f5cb8
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

24,009
zabbixzabbix-communityVerified publisher7.1.04 of 5See more

zabbix zabbix-community 7.1.0

4 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

13,875
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,104
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

5,378
flux2fluxcd-community2.19.01 of 7See more

flux2 fluxcd-community 2.19.0

1 of the 7 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/kustomize-controller:v1.9.23aecec8bafdb
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

2,957
vaultwardengissilabs1.4.21 of 1See more

vaultwarden gissilabs 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,756
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
curl@7.58.0-2ubuntu3.22
7.58.0-2ubuntu3.24+esm11

Open the chart page →

5,557
zammadzammadOfficialVerified publisher18.2.01 of 5See more

zammad zammad 18.2.0

1 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

6,849
clamavwiremindVerified publisher3.7.31 of 1See more

clamav wiremind 3.7.3

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
clamav/clamav:1.4.3_base629a3050df6a
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,060
atlantisatlantis6.15.11 of 1See more

atlantis atlantis 6.15.1

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,892
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.26

Open the chart page →

9,194
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm6
milvusdb/milvus:v2.2.13a3a55e1c1497
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.25+esm6

Open the chart page →

32,353
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

10,648
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
penpotapp/frontend:2.17.294fa2864d8fc
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

4,412
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

2,717
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
curl@7.88.1-10+deb12u4
no fix listed

Open the chart page →

4,808
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

19,497
dragonflydragonflyVerified publisher1.8.42 of 3See more

dragonfly dragonfly 1.8.4

2 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.4a1b52779c4dd
curl@7.88.1-10+deb12u15
no fix listed
dragonflyoss/scheduler:v2.5.2-rc.06d710dc2bae0
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

3,663
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
curl@8.18.0-1ubuntu2.3
8.18.0-1ubuntu2.4

Open the chart page →

1,587
pulsarapache4.7.02 of 10See more

pulsar apache 4.7.0

2 of the 10 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
curl@8.18.0-r0
8.21.0-r0
grafana/grafana:12.4.1e932bd6ed0e0
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

9,869
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

3,645
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

6,949
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
curl@7.88.1-10+deb12u15
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
curl@7.88.1-10+deb12u15
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.12
langgenius/dify-sandbox:0.2.15750e1111426e
curl@8.19.0-3
no fix listed
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

22,115
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/kong:3.92a8cf3b110cd
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12

Open the chart page →

1,174
oktetooktetoOfficialVerified publisher0.0.0-2026-08-172 of 10See more

okteto okteto 0.0.0-2026-08-17

2 of the 10 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/okteto/buildkit:0.0.0-2026-08-1714527ca5d2a9
curl@8.20.0-r0
8.22.0-r0
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-173e56bdd1b90d
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

5,491
yourlsyourlsOfficialVerified publisher8.9.111 of 2See more

yourls yourls 8.9.11

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.69b220ea83329
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,233
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm18
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm18

Open the chart page →

23,992
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.02 of 5See more

openproject openproject-helm-charts 13.11.0

2 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
curl@7.88.1-10+deb12u12
no fix listed
openproject/openproject:17.8.0-slim48952034215d
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

19,998
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

11,402
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
curl@7.88.1-10+deb12u15
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

7,234
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.26
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.26
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.26

Open the chart page →

33,907
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
curl@7.88.1-10+deb12u6
no fix listed

Open the chart page →

6,550
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
google/cloud-sdk:alpinef7d3e6d6d4f4
curl@8.20.0-r0
8.22.0-r0
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

8,387
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

5,278
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

6,012
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
curl@7.68.0-1ubuntu2.21
7.68.0-1ubuntu2.25+esm6
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.26

Open the chart page →

12,830

Container images carrying it

1,531 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.22.0-r0
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
curl@7.81.0-1ubuntu1.25
7.81.0-1ubuntu1.26
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.12
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm11
1
gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine6d35276c2562
curl@8.20.0-r0
8.22.0-r0
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.19+esm18
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.19+esm18
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm18
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.25+esm6
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm18
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.25+esm6
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
curl@8.5.0-2ubuntu10.1
8.5.0-2ubuntu10.12
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
curl@7.88.1-10+deb12u7
no fix listed
1
ghcr.io/aardbol/opencode-server:v1.18.23-alpine7930061993f7
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/aeharding/voyager:latest779759172676
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
curl@8.14.1-2+deb13u2
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
ghcr.io/apache/ats-ingress:latest2d4d776f6362
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.26
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
curl@8.16.0-4~bpo13+1
no fix listed
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.26
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.26
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
curl@8.14.1-2+deb13u5
no fix listed
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
curl@7.88.1-10+deb12u7
no fix listed
1
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
curl@7.88.1-10+deb12u12
no fix listed
1
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.12
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.26
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/bitwarden/web:2026.8.00767b242240d
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.25+esm6
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.12
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
curl@7.88.1-10+deb12u6
no fix listed
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.26
1
ghcr.io/caninehq/canine:latesta058034ca006
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/cleanuparr/cleanuparr:2.10.5c7cd53ad559a
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.