StackRadar

CVE-2026-13608

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,397
of 17,790 indexed, latest versions
Container images
1,266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,397 of 17,790 indexed charts deploy, on 1,266 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+36 more1:8.14.1-2+deb13u3+e4906
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0360
OSV records
ALPINE-CVE-2026-13608CGA-wfwx-52wx-xm5jDEBIAN-CVE-2026-13608UBUNTU-CVE-2026-13608ECHO-f292-4a07-579c
Also known as
CGA-x99g-hxrw-x4jm

Charts affected

1,397 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/nextcloud:34.0.4:34.0.4-apache8418c398d767
curl@8.14.1-2+deb13u5
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
curl@8.14.1-2+deb13u2
no fix listed
1
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
curl@8.14.1-2+deb13u4
no fix listed
1
library/nextcloud:34.0.4-apachede4ad9389386
curl@8.14.1-2+deb13u4
no fix listed
1
library/nginx:1.27.409369da6b103
curl@7.88.1-10+deb12u12
no fix listed
1
library/nginx:1.291881968aff6f
curl@8.14.1-2+deb13u2
no fix listed
1
library/nginx:1.31.0-alpine2f07d83bf561
curl@8.19.0-r0
8.22.0-r0
1
library/nginx:1.31.3-alpine4a73073bd557
curl@8.21.0-r0
8.22.0-r0
1
library/nginx:1.29.8-alpine5616878291a2
curl@8.17.0-r1
8.22.0-r0
1
library/nginx:1.276784fb0834aa
curl@7.88.1-10+deb12u12
no fix listed
1
library/nginx:1.25.167f9a4f10d14
curl@7.88.1-10+deb12u1
no fix listed
1
library/nginx:1.25.49ff236ed47fe
curl@7.88.1-10+deb12u5
no fix listed
1
library/nginx:1.31a53fc6c27208
curl@8.14.1-2+deb13u5
no fix listed
1
library/nginx:1.28-alpinea8b39bd9cf0f
curl@8.17.0-r1
8.22.0-r0
1
library/nginx:1.27.3fb197595ebe7
curl@7.88.1-10+deb12u8
no fix listed
1
library/node:208f693eaa7e0a
curl@7.88.1-10+deb12u14
no fix listed
1
library/node:latestf5d1cc40abc1
curl@8.14.1-2+deb13u4
no fix listed
1
library/php:8-fpm-alpine22a4c414bb8e
curl@8.21.0-r0
8.22.0-r0
1
library/php:8.4-fpm59fa733c9af6
curl@8.14.1-2+deb13u4
no fix listed
1
library/postgres:18.3-alpine54451ecb8ab3
curl@8.17.0-r1
8.22.0-r0
1
library/postgres:18.4-alpine3.249a8afca54e78
curl@8.21.0-r0
8.22.0-r0
1
library/python:3.1070c9cc675605
curl@8.14.1-2+deb13u4
no fix listed
1
library/python:3.8d41127070014
curl@7.88.1-10+deb12u7
no fix listed
1
library/python:3.9da5aee29682d
curl@8.14.1-2
no fix listed
1
library/redmine:6.1.204ac44a2595b
curl@8.14.1-2+deb13u3
no fix listed
1
library/telegraf:1.27507a3eecf809
curl@7.88.1-10+deb12u5
no fix listed
1
library/tomcat:11.0.25-jdk17-temurin-noble9e1d2afa6898
curl@8.5.0-2ubuntu10.12
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
curl@7.88.1-10+deb12u5
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
curl@8.14.1-2+deb13u3
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
curl@8.14.1-2+deb13u2
no fix listed
1
library/xwiki:lts-postgres-tomcat56490ac14a31
curl@8.5.0-2ubuntu10.13
no fix listed
1
librenms/librenms:26.8.28194a4a9ff49
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/bazarr:latesta20fb11a440d
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/bookstack:26.05.202605282ebf97852661
curl@8.19.0-r0
8.22.0-r0
1
linuxserver/calibre-web:0.6.24241009026e6f
curl@8.5.0-2ubuntu10.6
no fix listed
1
linuxserver/deluge:2.2.09505c64720af
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/foldingathome:8.5.67477f6455f47
curl@8.5.0-2ubuntu10.13
no fix listed
1
linuxserver/foldingathome:7.6.219a997426d71e
curl@8.5.0-2ubuntu10.1
no fix listed
1
linuxserver/heimdall:2.8.3287e48152967
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/lidarr:3.1.0c74c32408fdf
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/mariadb:latestcb61ec331e80
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/plex:1.43.41f6f97d76e7b
curl@8.18.0-1ubuntu2.5
no fix listed
1
linuxserver/plex:1.43.22785a6ad64d3
curl@8.5.0-2ubuntu10.10
no fix listed
1
linuxserver/prowlarr:version-2.4.0.53974fd7a166c8f4
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/prowlarr:2.5.291844fa2c927
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/prowlarr:2.4.0.5397-ls149a46d0ce0a823
curl@8.19.0-r0
8.22.0-r0
1
linuxserver/qbittorrent:latesta00b6a597a38
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/qbittorrent:5.2.2dd24a5f3db32
curl@8.19.0-r0
8.22.0-r0
1
linuxserver/radarr:version-6.2.1.10461549c4a075496
curl@8.21.0-r0
8.22.0-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.