StackRadar

CVE-2026-13608

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,397
of 17,790 indexed, latest versions
Container images
1,266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,397 of 17,790 indexed charts deploy, on 1,266 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+36 more1:8.14.1-2+deb13u3+e4906
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0360
OSV records
ALPINE-CVE-2026-13608CGA-wfwx-52wx-xm5jDEBIAN-CVE-2026-13608UBUNTU-CVE-2026-13608ECHO-f292-4a07-579c
Also known as
CGA-x99g-hxrw-x4jm

Charts affected

1,397 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
n8nio/n8n:2.38.45d9f0cc5672b
curl@8.21.0-r0
8.22.0-r0
1
n8nio/n8n:2.39.5cfa04788a34a
curl@8.21.0-r0
8.22.0-r0
1
n8nio/n8n:2.36.8cfe2704ff858
curl@8.21.0-r0
8.22.0-r0
1
netbirdio/dashboard:v2.91.0aae926912ca4
curl@8.21.0-r0
8.22.0-r0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
curl@8.18.0-1ubuntu2.3
no fix listed
1
netdata/netdata:v2.11.0c45c71eb23ff
curl@8.14.1-2+deb13u4
no fix listed
1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
curl@8.17.0-r1
8.22.0-r0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
curl@8.14.1-2+deb13u2
no fix listed
1
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
curl@8.14.1-2
no fix listed
1
nginxinc/nginx-unprivileged:latest4210a3296e7c
curl@8.14.1-2+deb13u4
no fix listed
1
nginxinc/nginx-unprivileged:1.31.2-alpine3.236320020c7da8
curl@8.19.0-r0
8.22.0-r0
1
nginxinc/nginx-unprivileged:1.31.4-alpine-otelb37d9945be77
curl@8.21.0-r0
8.22.0-r0
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
curl@8.14.1-2+deb13u2
no fix listed
1
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
curl@8.17.0-r1
8.22.0-r0
1
nginxinc/nginx-unprivileged:1.31.3-alpinef972e5322b97
curl@8.21.0-r0
8.22.0-r0
1
nirmalnaveen/supermario:latest8541a39162f3
curl@7.88.1-10+deb12u4
no fix listed
1
nocodb/nocodb:latest4b760f0d2547
curl@8.20.0-r0
8.22.0-r0
1
nodered/node-red:5.0.410f40d0a83e7
curl@8.21.0-r0
8.22.0-r0
1
nodered/node-red:4.1.10-minimald73ae167cb9b
curl@8.17.0-r1
8.22.0-r0
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
curl@8.14.1-2+deb13u4
no fix listed
1
novosga/novosga:latest34b9acbe6e51
curl@8.17.0-r1
8.22.0-r0
1
obolnetwork/helios:e10e753cb7e97d39d46
curl@8.5.0-2ubuntu10.6
no fix listed
1
octoboxio/octobox:latestd909041c46eb
curl@8.17.0-r1
8.22.0-r0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
curl@7.88.1-10+deb12u14
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
curl@7.88.1-10+deb12u6
no fix listed
1
oled01/automx2:2025.1.105d3e398e675
curl@7.88.1-10+deb12u12
no fix listed
1
olvid/bot-daemon:2.0.1e0e6b165d879
curl@8.5.0-2ubuntu10.8
no fix listed
1
oneuptime/probe:release1069c9458fe7
curl@7.88.1-10+deb12u15
no fix listed
1
oneuptime/runner:releasef6f2c1c536bc
curl@8.14.1-2+deb13u5
no fix listed
1
opea/chatqna:1.038c51b791efa
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codegen:1.058f91683892d
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
curl@7.88.1-10+deb12u5
no fix listed
1
opea/codetrans:1.0e2436483b73d
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
curl@7.88.1-10+deb12u5
no fix listed
1
opea/docsum:1.03eaa91849512
curl@7.88.1-10+deb12u7
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
curl@7.88.1-10+deb12u5
no fix listed
1
opea/speecht5:1.0249afad3d268
curl@7.88.1-10+deb12u7
no fix listed
1
openaev/platform:3.260904.00a12ce8b3db9
curl@8.5.0-2ubuntu10.12
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
curl@7.88.1-10+deb12u8
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
curl@8.5.0-2ubuntu10.6
no fix listed
1
opencloudeu/opencloud:7.2.46d992ccc5f1c
curl@8.21.0-r0
8.22.0-r0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
curl@7.88.1-10+deb12u14
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
curl@8.14.1-2+deb13u4
no fix listed
1
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
curl@7.88.1-10+deb12u14
no fix listed
1
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
curl@7.88.1-10+deb12u14
no fix listed
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
curl@7.88.1-10+deb12u7
no fix listed
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
curl@7.88.1-10+deb12u7
no fix listed
1
opencsghq/kubectl:latestb6d87e1048c2
curl@7.88.1-10+deb12u12
no fix listed
1
opencsghq/label-studio:v2.5.047e22aa71870
curl@8.14.1-2+deb13u4
no fix listed
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
curl@8.14.1-2+deb13u4
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.