CVE-2026-13608
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.4
- base score, highest
- EPSS
- 0.006
- 49th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,374
- of 17,792 indexed, latest versions
- Container images
- 1,229
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,374 of 17,792 indexed charts deploy, on 1,229 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+36 more | 1:8.14.1-2+deb13u3+e4 | 878 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 351 |
- OSV records
- ALPINE-CVE-2026-13608CGA-wfwx-52wx-xm5jDEBIAN-CVE-2026-13608UBUNTU-CVE-2026-13608ECHO-f292-4a07-579c
- Also known as
- CGA-x99g-hxrw-x4jm
Charts affected
1,374 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
1,229 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pockost/ | 7f5d293cbe4e | curl | no fix listed | 1 |
| polyaxon/ | 2b55c3265a90 | curl | no fix listed | 1 |
| polyaxon/ | c186bd9834c0 | curl | no fix listed | 1 |
| posit/ | 527493ef621b | curl | no fix listed | 1 |
| postgis/ | 7e00e8c3539f | curl | no fix listed | 1 |
| powerdns/ | 33aadc74a8d6 | curl | no fix listed | 1 |
| praravind1801/ | f29d637b9ce1 | curl | no fix listed | 1 |
| prefecthq/ | 1df4b5b6238a | curl | no fix listed | 1 |
| prefecthq/ | f518ebb9c353 | curl | no fix listed | 1 |
| pretix/ | 5df3b7aa852e | curl | no fix listed | 1 |
| prodrigestivill/ | f70742ebe42b | curl | no fix listed | 1 |
| prom/ | 71c2e988af06 | curl | no fix listed | 1 |
| prowlercloud/ | 4f252d579be2 | curl | no fix listed | 1 |
| qjoly/ | ec94d3bdc035 | curl | no fix listed | 1 |
| qonstrukt/ | 089af7925aa1 | curl | no fix listed | 1 |
| quickwit/ | d29332bdadcc | curl | no fix listed | 1 |
| radarbase/ | e1758508e033 | curl | no fix listed | 1 |
| radarbase/ | fcd973d4796d | curl | no fix listed | 1 |
| readysettech/ | 588f3507280e | curl | no fix listed | 1 |
| readysettech/ | 67a83203ce60 | curl | no fix listed | 1 |
| reallibrephotos/ | 98a13dabbadc | curl | no fix listed | 1 |
| redash/ | 00d813437db5 | curl | no fix listed | 1 |
| redash/ | c5c9148f5c38 | curl | no fix listed | 1 |
| redimp/ | 778bf30da3da | curl | no fix listed | 1 |
| redocly/ | 2e26bb660574 | curl | 8.22.0-r0 | 1 |
| redpandadata/ | 468bd13a9f2b | curl | no fix listed | 1 |
| replicated/ | 8751b4963250 | curl | 8.22.0-r0 | 1 |
| reportportal/ | 06cdf299b397 | curl | 8.22.0-r0 | 1 |
| reportportal/ | aea8747cb639 | curl | 8.22.0-r0 | 1 |
| rhasspy/ | e532f0dbc6b2 | curl | no fix listed | 1 |
| robiningelbrecht/ | 40842cdfd616 | curl | 8.22.0-r0 | 1 |
| robustadev/ | 0457a51e36e8 | curl | 8.22.0-r0 | 1 |
| rocketchat/ | cfba5c20a5cc | curl | no fix listed | 1 |
| rommapp/ | 3512f2ca4557 | curl | 8.22.0-r0 | 1 |
| roundcube/ | 17d9d9580962 | curl | no fix listed | 1 |
| rtuszik/ | 21549c60f9e6 | curl | no fix listed | 1 |
| rustfs/ | 3c2d55977829 | curl | 8.22.0-r0 | 1 |
| rustfs/ | 7d49faa88c04 | curl | 8.22.0-r0 | 1 |
| rustfs/ | 800cf3f352a0 | curl | 8.22.0-r0 | 1 |
| santisbon/ | 8ee3a1697227 | curl | no fix listed | 1 |
| sashafefler/ | f96d7804c0ca | curl | no fix listed | 1 |
| sbs20/ | dad1fd6e9a98 | curl | no fix listed | 1 |
| scholtz2/ | e9af7d8ff6bb | curl | no fix listed | 1 |
| scholtz2/ | 1ec63eca86b6 | curl | no fix listed | 1 |
| scholtz2/ | 70263d8fab5b | curl | no fix listed | 1 |
| scholtz2/ | 3a3b3d3277d2 | curl | no fix listed | 1 |
| scholtz2/ | 6770214bc881 | curl | no fix listed | 1 |
| securecodebox/ | afcefbd56d61 | curl | 8.22.0-r0 | 1 |
| selenium/ | 5ac71fd8dd1e | curl | no fix listed | 1 |
| selenium/ | 74a5c1c90f95 | curl | no fix listed | 1 |