StackRadar

CVE-2026-13608

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,397
of 17,790 indexed, latest versions
Container images
1,266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,397 of 17,790 indexed charts deploy, on 1,266 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+36 more1:8.14.1-2+deb13u3+e4906
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0360
OSV records
ALPINE-CVE-2026-13608CGA-wfwx-52wx-xm5jDEBIAN-CVE-2026-13608UBUNTU-CVE-2026-13608ECHO-f292-4a07-579c
Also known as
CGA-x99g-hxrw-x4jm

Charts affected

1,397 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hoppscotch/hoppscotch:2026.8.0d50725df661f
curl@8.21.0-r0
8.22.0-r0
1
huacnlee/gobackup:v3.1.1560be93229a5
curl@8.21.0-r0
8.22.0-r0
1
hwdsl2/ipsec-vpn-server:latest2e939ffe5913
curl@8.20.0-r0
8.22.0-r0
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
curl@7.88.1-10+deb12u1
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
curl@8.14.1-2+deb13u2
no fix listed
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
curl@8.14.1-2+deb13u2
no fix listed
1
instill/model-backend:611f0f2e980125e5ba5
curl@8.14.1-2+deb13u2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
curl@7.88.1-10+deb12u5
no fix listed
1
inventree/inventree:1.5.4a946ec09da3e
curl@8.14.1-2+deb13u4
no fix listed
1
istio/examples-helloworld-v1:latest328b237e4fb1
curl@7.88.1-10+deb12u5
no fix listed
1
istio/examples-helloworld-v2:latest0a7f02b2c7c9
curl@7.88.1-10+deb12u5
no fix listed
1
istio/install-cni:1.23.6ab34c4740f44
curl@8.5.0-2ubuntu10.6
no fix listed
1
istio/install-cni:1.29.0ce27c9ce43c8
curl@8.5.0-2ubuntu10.6
no fix listed
1
istio/pilot:1.29.0325156535773
curl@8.5.0-2ubuntu10.6
no fix listed
1
istio/pilot:1.23.69c3d6a218181
curl@8.5.0-2ubuntu10.6
no fix listed
1
istio/pilot:1.29.1f8b0e412ac4a
curl@8.5.0-2ubuntu10.7
no fix listed
1
istio/ztunnel:1.25.005f3972d80a9
curl@8.5.0-2ubuntu10.6
no fix listed
1
itzg/bungeecord:latest1c59f9631f3b
curl@8.18.0-1ubuntu2.4
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
curl@8.5.0-2ubuntu10.13
no fix listed
1
itzg/minecraft-server:2026.9.1e8640538dac5
curl@8.5.0-2ubuntu10.13
no fix listed
1
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
no fix listed
1
jaedb/iris:latest048cfbf58d57
curl@7.88.1-10+deb12u12
no fix listed
1
jbtronics/part-db1:latest5db71f6db59d
curl@7.88.1-10+deb12u15
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
curl@8.14.1-2+deb13u2
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
curl@8.14.1-2+deb13u2
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
curl@7.88.1-10+deb12u8
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
curl@8.14.1-2+deb13u2
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
curl@7.88.1-10+deb12u6
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
curl@7.88.1-10+deb12u12
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
curl@7.88.1-10+deb12u8
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
curl@7.88.1-10+deb12u7
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
curl@7.88.1-10+deb12u5
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
curl@8.14.1-2+deb13u4
no fix listed
1
jesec/flood:4.14.3c887dad96b40
curl@8.20.0-r1
8.22.0-r0
1
jhonbrownn/elchi:v1.5.146936e4f1caeb
curl@8.21.0-r0
8.22.0-r0
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
curl@7.88.1-10+deb12u5
no fix listed
1
jitesoft/kubectl:latest9996dd28914f
curl@8.21.0-r0
8.22.0-r0
1
jordan/icinga2:latestf75025fe8ea8
curl@7.88.1-10+deb12u14
no fix listed
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
curl@7.88.1-10+deb12u15
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
curl@8.5.0-2ubuntu10.9
no fix listed
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
curl@8.20.0-r0
8.22.0-r0
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
curl@8.5.0-2ubuntu10.4
no fix listed
1
kanboard/kanboard:v1.2.548df6c4339134
curl@8.21.0-r0
8.22.0-r0
1
kayrosuno/kping:latestf3bd44b29b0d
curl@8.5.0-2ubuntu10.7
no fix listed
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
curl@8.17.0-r1
8.22.0-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
curl@8.17.0-r1
8.22.0-r0
1
kimai/kimai2:2.67.03084f1e5ecdc
curl@7.88.1-10+deb12u15
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
curl@7.88.1-10+deb12u14
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
curl@8.14.1-2+deb13u4
no fix listed
1
kixote/typemill4e9dff179519
curl@8.14.1-2+deb13u4
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.