StackRadar

CVE-2026-11856

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,704
of 17,790 indexed, latest versions
Container images
1,530
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,704 of 17,790 indexed charts deploy, on 1,530 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16+109 more7.35.0-1ubuntu2.20+esm22, 7.47.0-1ubuntu2.19+esm18, 7.58.0-2ubuntu3.24+esm11, 7.68.0-1ubuntu2.25+esm6+4 more1,313
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0217
OSV records
ALPINE-CVE-2026-11856DEBIAN-CVE-2026-11856UBUNTU-CVE-2026-11856ECHO-895d-0fcf-45bd
Also known as
USN-8651-1

Charts affected

1,704 by stars
ChartLatestAffected imagesRadar Score
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm6
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm6
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm6

Open the chart page →

30,813
home-assistantalekcVerified publisher2.11.21 of 1See more

home-assistant alekc 2.11.2

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
curl@8.20.0-r1
8.21.0-r0

Open the chart page →

2,139
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,650
home-assistantandrenarchyVerified publisher14.104.01 of 1See more

home-assistant andrenarchy 14.104.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
curl@8.20.0-r1
8.21.0-r0

Open the chart page →

2,139
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

6,531
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
curl@7.68.0-1ubuntu2.21
7.68.0-1ubuntu2.25+esm6

Open the chart page →

12,166
cortexcortex3.3.81 of 4See more

cortex cortex 3.3.8

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/nginx:1.3105b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,948
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12

Open the chart page →

1,544
kubernetes-ingresshaproxytechVerified publisher1.54.11 of 1See more

kubernetes-ingress haproxytech 1.54.1

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:3.2.156185ab228aa6
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

400
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.26

Open the chart page →

4,954
docmosthelmforgeVerified publisher1.2.121 of 4See more

docmost helmforge 1.2.12

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,113
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,215
mercuremercureOfficialVerified publisher0.24.01 of 1See more

mercure mercure 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
dunglas/mercure:v0.24.080fcb704a741
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,416
meshery-operatormesheryOfficialVerified publisher1.0.701 of 2See more

meshery-operator meshery 1.0.70

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
alpine/k8s:1.35.6b7a12c5ddf26
curl@8.20.0-r1
8.21.0-r0

Open the chart page →

2,432
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

8,692
passboltpassbolt2.1.11 of 6See more

passbolt passbolt 2.1.1

1 of the 6 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

13,523
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
curl@7.81.0-1ubuntu1.25
7.81.0-1ubuntu1.26

Open the chart page →

2,955
thehivestrangebee-helmOfficialVerified publisher1.0.73 of 7See more

thehive strangebee-helm 1.0.7

3 of the 7 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
curl@7.88.1-10+deb12u12
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
curl@7.88.1-10+deb12u12
no fix listed
strangebee/thehive:5.8.0-1a7f7b05fba24
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

16,220
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

14,327
agonesagones1.60.01 of 5See more

agones agones 1.60.0

1 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.49ccd82364762
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,122
minecraft-overvieweralphani-helm-chartsVerified publisher0.1.01 of 3See more

minecraft-overviewer alphani-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,402
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
curl@8.18.0-1ubuntu2.3
8.18.0-1ubuntu2.4

Open the chart page →

8,923
cloudflaredartur9010Verified publisher1.0.91 of 3See more

cloudflared artur9010 1.0.9

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

3,008
openvpn-asas-helm-chartOfficialVerified publisher0.2.11 of 1See more

openvpn-as as-helm-chart 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
openvpn/openvpn-as:latest2253c10ec652
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12

Open the chart page →

2,722
baserowbaserow-chartVerified publisher1.0.562 of 6See more

baserow baserow-chart 1.0.56

2 of the 6 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
curl@8.14.1-2+deb13u4
no fix listed
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
curl@7.88.1-10+deb12u6
no fix listed

Open the chart page →

17,413
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm6
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm6

Open the chart page →

53,052
headwind-mdmchristianhuthVerified publisher5.10.21 of 2See more

headwind-mdm christianhuth 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
headwindmdm/hmdm:0.1.93550b4840840
curl@7.81.0-1ubuntu1.25
7.81.0-1ubuntu1.26

Open the chart page →

5,929
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
dolibarr/dolibarr:22.0.47ad88fc9b13c
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

9,208
seafiledatamateVerified publisher0.6.02 of 6See more

seafile datamate 0.6.0

2 of the 6 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
curl@7.88.1-10+deb12u6
no fix listed
datamate/seafile-professional:11.0.202dd66b722464
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.26

Open the chart page →

27,426
jellyfindjjudas21Verified publisher4.0.81 of 1See more

jellyfin djjudas21 4.0.8

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

2,626
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
redocly/redoc:latest2e26bb660574
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

3,282
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

2,583
geonode-k8sgeonode-k8sVerified publisher2.0.03 of 10See more

geonode-k8s geonode-k8s 2.0.0

3 of the 10 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
curl@7.81.0-1ubuntu1.24
7.81.0-1ubuntu1.26
geonode/geoserver_data:2.28.4-latest435cbc5f3f05
curl@8.20.0-r1
8.21.0-r0
nginxinc/nginx-unprivileged:1.31.2-alpine3.236320020c7da8
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

14,112
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,917
glpiglpi-conteiner0.1.02 of 3See more

glpi glpi-conteiner 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
curl@8.14.1-2+deb13u4
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
curl@7.88.1-10+deb12u6
no fix listed

Open the chart page →

12,359
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
dolibarr/dolibarr:24.0.069ec52e3b7ef
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

4,172
karakeephelmforgeVerified publisher1.2.92 of 3See more

karakeep helmforge 1.2.9

2 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

9,557
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,664
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

3,407
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
apache/hertzbeat-collector:1.8.0a2bab1be574c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

14,181
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

10,522
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.12

Open the chart page →

1,729
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
curl@7.68.0-1ubuntu2.25
7.68.0-1ubuntu2.25+esm6

Open the chart page →

6,350
kubeflowkubeflow1.6.23 of 45See more

kubeflow kubeflow 1.6.2

3 of the 45 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm11
istio/proxyv2:1.14.1df69c1a7af7c
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.25+esm6
library/python:3.7eedf63967cdb
curl@7.88.1-10+deb12u1
no fix listed

Open the chart page →

97,217
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.25+esm6

Open the chart page →

10,573
testkubekubeshop2.13.22 of 5See more

testkube kubeshop 2.13.2

2 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
kubeshop/testkube-minio:2025.10d8e1af6aca99
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

5,151
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.12

Open the chart page →

5,849
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12

Open the chart page →

4,070
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

7,997
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
gradiant/open5gs-dbctl:0.10.3332031245fce
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12

Open the chart page →

9,305

Container images carrying it

1,530 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/umami-software/umami:3.0.328f263fe06f7
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.26
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.26
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.26
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
curl@7.88.1-10+deb12u1
no fix listed
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
curl@7.88.1-10+deb12u4
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
curl@7.88.1-10+deb12u6
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
curl@7.58.0-2ubuntu3.18
7.58.0-2ubuntu3.24+esm11
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.26
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0014ce435c77651e
curl@8.14.1-2+deb13u5
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
curl@7.88.1-10+deb12u8
no fix listed
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
curl@7.81.0-1ubuntu1.25
7.81.0-1ubuntu1.26
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.12
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
curl@7.88.1-10+deb12u15
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
curl@8.18.0-1ubuntu2.3
8.18.0-1ubuntu2.4
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.26
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
curl@1:8.14.1-2+deb13u3+e1
8.14.1-2+e18
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
curl@8.14.1-2+e14
8.14.1-2+e18
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
curl@7.88.1-10+deb12u7
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
curl@7.88.1-10+deb12u7
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
curl@7.88.1-10+deb12u4
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
curl@7.88.1-10+deb12u14
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
curl@7.88.1-10+deb12u8
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm11
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.25+esm6
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
curl@7.88.1-10+deb12u5
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.26
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
curl@8.18.0-1ubuntu2.3
8.18.0-1ubuntu2.4
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.26
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.26
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.