StackRadar

CVE-2026-13608

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,397
of 17,790 indexed, latest versions
Container images
1,266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,397 of 17,790 indexed charts deploy, on 1,266 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+36 more1:8.14.1-2+deb13u3+e4906
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0360
OSV records
ALPINE-CVE-2026-13608CGA-wfwx-52wx-xm5jDEBIAN-CVE-2026-13608UBUNTU-CVE-2026-13608ECHO-f292-4a07-579c
Also known as
CGA-x99g-hxrw-x4jm

Charts affected

1,397 by stars
ChartLatestAffected imagesRadar Score
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
curl@8.18.0-1ubuntu2.2
no fix listed

Open the chart page →

9,505
akto-central-setupakto1.1.104 of 5See more

akto-central-setup akto 1.1.10

4 of the 5 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
curl@8.18.0-1ubuntu2.3
no fix listed
library/eclipse-temurin:211f79c73404fb
curl@8.18.0-1ubuntu2.5
no fix listed
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2b53a854bd7c1
curl@8.5.0-2ubuntu10.12
no fix listed
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
curl@8.5.0-2ubuntu10.12
no fix listed

Open the chart page →

5,118
akto-dashboardakto0.1.71 of 1See more

akto-dashboard akto 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
curl@8.5.0-2ubuntu10.12
no fix listed

Open the chart page →

1,206
akto-dbabsakto0.1.91 of 1See more

akto-dbabs akto 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
curl@8.5.0-2ubuntu10.12
no fix listed

Open the chart page →

1,170
akto-hybrid-redactakto1.44.61 of 5See more

akto-hybrid-redact akto 1.44.6

1 of the 5 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
curl@8.18.0-1ubuntu2.5
no fix listed

Open the chart page →

4,098
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

2,826
akto-mini-testingakto1.45.72 of 5See more

akto-mini-testing akto 1.45.7

2 of the 5 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
curl@7.88.1-10+deb12u15
no fix listed
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
curl@8.18.0-1ubuntu2.3
no fix listed

Open the chart page →

6,580
akto-regional-setupakto1.3.13 of 9See more

akto-regional-setup akto 1.3.1

3 of the 9 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
curl@8.18.0-1ubuntu2.2
no fix listed
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
curl@8.18.0-1ubuntu2.4
no fix listed
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

7,828
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

1,474
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
curl@8.5.0-2ubuntu10.6
no fix listed

Open the chart page →

4,866
akto-threat-backendakto0.1.51 of 2See more

akto-threat-backend akto 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

1,553
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

1,585
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
curl@8.5.0-2ubuntu10.6
no fix listed

Open the chart page →

3,487
browserlessalekcVerified publisher1.2.71 of 1See more

browserless alekc 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
curl@8.5.0-2ubuntu10.13
no fix listed

Open the chart page →

2,143
cross-seedalekcVerified publisher7.19.01 of 1See more

cross-seed alekc 7.19.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,385
esphomealekcVerified publisher2.8.11 of 1See more

esphome alekc 2.8.1

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
esphome/esphome:2026.8.285abea33854b
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

3,179
excalidashalekcVerified publisher1.4.01 of 2See more

excalidash alekc 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.6.04ec5b20c0303
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

906
komodoalekcVerified publisher3.1.01 of 1See more

komodo alekc 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,941
plexalekcVerified publisher2.10.11 of 1See more

plex alekc 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
linuxserver/plex:1.43.41f6f97d76e7b
curl@8.18.0-1ubuntu2.5
no fix listed

Open the chart page →

647
sambaalekcVerified publisher1.1.01 of 1See more

samba alekc 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,142
alertigatealertigate0.5.11 of 1See more

alertigate alertigate 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/feresberbeche/alertigate:1.2.1628d49e0e01b
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,560
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

6,352
flaresolverralexmorbo-flaresolverrVerified publisher0.2.01 of 1See more

flaresolverr alexmorbo-flaresolverr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

27,554
lidarralexmorbo-lidarrVerified publisher0.1.21 of 1See more

lidarr alexmorbo-lidarr 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,876
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,624
nginx-sni-proxyalexpressoVerified publisher1.0.21 of 1See more

nginx-sni-proxy alexpresso 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,849
wireguardalexpressoVerified publisher0.1.31 of 2See more

wireguard alexpresso 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
linuxserver/wireguard:latestbf03578ef731
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

786
alluredeckalluredeckVerified publisher0.24.01 of 2See more

alluredeck alluredeck 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/mkutlak/alluredeck-ui:0.41.0c19509b1b336
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,280
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
curl@8.5.0-2ubuntu10.11
no fix listed

Open the chart page →

3,691
anchore-admission-controlleranchore-charts0.8.51 of 2See more

anchore-admission-controller anchore-charts 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

7,605
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

5,865
stalwartandibraeuVerified publisher1.0.21 of 1See more

stalwart andibraeu 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.16.1425001929f36a
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,609
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,294
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

7,312
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

4,063
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

5,591
ansible-playbook-operatoransible-playbook-operatorVerified publisher0.1.71 of 1See more

ansible-playbook-operator ansible-playbook-operator 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,340
antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher0.2.01 of 1See more

antigenic-docuseal-helm-chart antigenic-docuseal-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
docuseal/docuseal:2.4.17493fd7f6728
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,766
antmediaantmediaVerified publisher3.1.01 of 4See more

antmedia antmedia 3.1.0

1 of the 4 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
curl@8.5.0-2ubuntu10.11
no fix listed

Open the chart page →

4,621
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

2,461
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

3,261
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

2,655
aceappscodeVerified publisher2026.9.111 of 2See more

ace appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

2,957
ace-installerappscodeVerified publisher2026.9.111 of 2See more

ace-installer appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

3,296
ace-installer-certifiedappscodeVerified publisher2026.9.111 of 2See more

ace-installer-certified appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

3,296
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

2,655
cluster-uiappscodeVerified publisher2026.9.111 of 1See more

cluster-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/cluster-ui:2.4.0f527d10769ac
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

371
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

2,655
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
curl@7.88.1-10+deb12u15
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
curl@8.16.0-4~bpo13+1
no fix listed

Open the chart page →

37,629
websiteappscodeVerified publisher2026.9.111 of 1See more

website appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-13608.

Container imageDigestPackageFixed in
ghcr.io/appscode/website:v2026.9.1170d9d1b78d39
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

371

Container images carrying it

1,266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/shesselink81/hesselinkme-nginx:v1.31.114f43beb13fc2
curl@8.21.0-r0
8.22.0-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
curl@8.5.0-2ubuntu10.10
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
curl@8.18.0-1ubuntu2.4
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
curl@8.14.1-2+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.gitlab.com/gitlab-ci-utils/curl-jq:latestb564745b6cb0
curl@8.21.0-r0
8.22.0-r0
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
curl@8.14.1-2+deb13u4
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
curl@8.20.0-r0
8.22.0-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
curl@8.14.1-2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
curl@7.88.1-10+deb12u4
no fix listed
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
curl@8.17.0-r1
8.22.0-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.