StackRadar

CVE-2026-11856

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,701
of 17,797 indexed, latest versions
Container images
1,518
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,701 of 17,797 indexed charts deploy, on 1,518 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16+109 more7.35.0-1ubuntu2.20+esm22, 7.47.0-1ubuntu2.19+esm18, 7.58.0-2ubuntu3.24+esm11, 7.68.0-1ubuntu2.25+esm6+4 more1,306
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0212
OSV records
ALPINE-CVE-2026-11856DEBIAN-CVE-2026-11856UBUNTU-CVE-2026-11856ECHO-895d-0fcf-45bd
Also known as
USN-8651-1

Charts affected

1,701 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-11856.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
curl@7.81.0-1ubuntu1.25
7.81.0-1ubuntu1.26

Open the chart page →

7,936

Container images carrying it

1,518 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
curl@7.88.1-10+deb12u6
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
curl@7.58.0-2ubuntu3.18
7.58.0-2ubuntu3.24+esm11
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.26
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/yourls/yourls:1.10.654082566391e
curl@8.14.1-2+deb13u5
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0014ce435c77651e
curl@8.14.1-2+deb13u5
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
curl@7.88.1-10+deb12u8
no fix listed
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
curl@7.81.0-1ubuntu1.25
7.81.0-1ubuntu1.26
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.12
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
curl@7.88.1-10+deb12u15
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
curl@8.18.0-1ubuntu2.3
8.18.0-1ubuntu2.4
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.26
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
curl@1:8.14.1-2+deb13u3+e1
8.14.1-2+e18
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
curl@8.14.1-2+e14
8.14.1-2+e18
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
curl@7.88.1-10+deb12u7
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
curl@7.88.1-10+deb12u7
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
curl@7.88.1-10+deb12u4
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
curl@7.88.1-10+deb12u14
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
curl@7.88.1-10+deb12u8
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm11
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.25+esm6
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
curl@7.88.1-10+deb12u5
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.26
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
curl@8.18.0-1ubuntu2.3
8.18.0-1ubuntu2.4
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.26
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.12
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.26
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
curl@8.19.0-r0
8.22.0-r0
1
quay.io/argoprojlabs/gitops-promoter:v0.39.0de07cc7c72b6
curl@8.14.1-2+deb13u4
no fix listed
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
curl@8.17.0-r1
8.22.0-r0
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
curl@7.58.0-2ubuntu3.20
7.58.0-2ubuntu3.24+esm11
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.26
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.26
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
curl@8.14.1-2+deb13u4
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
curl@8.5.0-2ubuntu10.11
8.5.0-2ubuntu10.12
1
quay.io/groundcover/tools:20260719b705e0cbe171
curl@1:8.14.1-2+deb13u3+e1
8.14.1-2+e18
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
curl@7.88.1-10+deb12u15
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
curl@7.88.1-10+deb12u14
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
curl@7.88.1-10+deb12u14
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.