CVE-2026-13608
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.4
- base score, highest
- EPSS
- 0.006
- 49th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,397
- of 17,790 indexed, latest versions
- Container images
- 1,266
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,397 of 17,790 indexed charts deploy, on 1,266 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+36 more | 1:8.14.1-2+deb13u3+e4 | 906 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 360 |
- OSV records
- ALPINE-CVE-2026-13608CGA-wfwx-52wx-xm5jDEBIAN-CVE-2026-13608UBUNTU-CVE-2026-13608ECHO-f292-4a07-579c
- Also known as
- CGA-x99g-hxrw-x4jm
Charts affected
1,397 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
1,266 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| hoppscotch/ | d50725df661f | curl | 8.22.0-r0 | 1 |
| huacnlee/ | 560be93229a5 | curl | 8.22.0-r0 | 1 |
| hwdsl2/ | 2e939ffe5913 | curl | 8.22.0-r0 | 1 |
| ildarmukhametzyanov/ | 15d23720a3ee | curl | no fix listed | 1 |
| instill/ | c4a393e601ed | curl | no fix listed | 1 |
| instill/ | ebe12f77a3f9 | curl | no fix listed | 1 |
| instill/ | e980125e5ba5 | curl | no fix listed | 1 |
| intelowlproject/ | 0b22e547ea6b | curl | no fix listed | 1 |
| inventree/ | a946ec09da3e | curl | no fix listed | 1 |
| istio/ | 328b237e4fb1 | curl | no fix listed | 1 |
| istio/ | 0a7f02b2c7c9 | curl | no fix listed | 1 |
| istio/ | ab34c4740f44 | curl | no fix listed | 1 |
| istio/ | ce27c9ce43c8 | curl | no fix listed | 1 |
| istio/ | 325156535773 | curl | no fix listed | 1 |
| istio/ | 9c3d6a218181 | curl | no fix listed | 1 |
| istio/ | f8b0e412ac4a | curl | no fix listed | 1 |
| istio/ | 05f3972d80a9 | curl | no fix listed | 1 |
| itzg/ | 1c59f9631f3b | curl | no fix listed | 1 |
| itzg/ | 8672e335dbef | curl | no fix listed | 1 |
| itzg/ | e8640538dac5 | curl | no fix listed | 1 |
| ixsystems/ | 19c218455cd2 | curl | no fix listed | 1 |
| jaedb/ | 048cfbf58d57 | curl | no fix listed | 1 |
| jbtronics/ | 5db71f6db59d | curl | no fix listed | 1 |
| jellyfin/ | 1694ff069f0c | curl | no fix listed | 1 |
| jellyfin/ | 17285f9cce63 | curl | no fix listed | 1 |
| jellyfin/ | 17c3a8d9dddb | curl | no fix listed | 1 |
| jellyfin/ | 333b64771663 | curl | no fix listed | 1 |
| jellyfin/ | 79fb3d73a3e9 | curl | no fix listed | 1 |
| jellyfin/ | 7ae36aab93ef | curl | no fix listed | 1 |
| jellyfin/ | 96b09723b22f | curl | no fix listed | 1 |
| jenkins/ | 95313257a8cd | curl | no fix listed | 1 |
| jenkins/ | de4fea113221 | curl | no fix listed | 1 |
| jertel/ | 3cbf63f9b7dc | curl | no fix listed | 1 |
| jesec/ | c887dad96b40 | curl | 8.22.0-r0 | 1 |
| jhonbrownn/ | 6936e4f1caeb | curl | 8.22.0-r0 | 1 |
| jhoncytech/ | 18c3ca1f411e | curl | no fix listed | 1 |
| jitesoft/ | 9996dd28914f | curl | 8.22.0-r0 | 1 |
| jordan/ | f75025fe8ea8 | curl | no fix listed | 1 |
| juicedata/ | 95008ba63318 | curl | no fix listed | 1 |
| jupyterhub/ | 3974ba945e65 | curl | no fix listed | 1 |
| jupyterjsc/ | aea53b13f235 | curl | 8.22.0-r0 | 1 |
| kafkace/ | 7adc206bf5a4 | curl | no fix listed | 1 |
| kanboard/ | 8df6c4339134 | curl | 8.22.0-r0 | 1 |
| kayrosuno/ | f3bd44b29b0d | curl | no fix listed | 1 |
| kenchrcum/ | 12fb213debf1 | curl | 8.22.0-r0 | 1 |
| kenchrcum/ | c326e28a8f5f | curl | 8.22.0-r0 | 1 |
| kimai/ | 3084f1e5ecdc | curl | no fix listed | 1 |
| kinseii/ | 7160eb143728 | curl | no fix listed | 1 |
| kitware/ | d7767d9b9da4 | curl | no fix listed | 1 |
| kixote/ | 4e9dff179519 | curl | no fix listed | 1 |