CVE-2026-13608
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.4
- base score, highest
- EPSS
- 0.006
- 49th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,376
- of 17,790 indexed, latest versions
- Container images
- 1,241
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,376 of 17,790 indexed charts deploy, on 1,241 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+36 more | 1:8.14.1-2+deb13u3+e4 | 885 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+12 more | 8.22.0-r0 | 356 |
- OSV records
- ALPINE-CVE-2026-13608CGA-wfwx-52wx-xm5jDEBIAN-CVE-2026-13608UBUNTU-CVE-2026-13608ECHO-f292-4a07-579c
- Also known as
- CGA-x99g-hxrw-x4jm
Charts affected
1,376 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
1,241 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| escaping/ | 87fa79255962 | curl | no fix listed | 1 |
| esphome/ | 4866347cb5b4 | curl | no fix listed | 1 |
| esphome/ | 85abea33854b | curl | no fix listed | 1 |
| esphome/ | 9ab8cc88b28c | curl | no fix listed | 1 |
| esphome/ | b2c6322700ac | curl | no fix listed | 1 |
| esphome/ | def8b6e4f517 | curl | no fix listed | 1 |
| espocrm/ | 1b5a24504ed9 | curl | no fix listed | 1 |
| espocrm/ | 4bd92daf5f0c | curl | 8.22.0-r0 | 1 |
| etherpad/ | 6020e7b57f4b | curl | 8.22.0-r0 | 1 |
| etherpad/ | b723fe5f2594 | curl | 8.22.0-r0 | 1 |
| ethpandaops/ | 1efa2fba6711 | curl | no fix listed | 1 |
| factoriotools/ | c6092b912bd1 | curl | no fix listed | 1 |
| factoriotools/ | e9227748c507 | curl | no fix listed | 1 |
| factoriotools/ | f7909f7361d6 | curl | no fix listed | 1 |
| falcosecurity/ | 932956d86c99 | curl | no fix listed | 1 |
| falcosecurity/ | d0cfe422d6ac | curl | 8.22.0-r0 | 1 |
| falcosecurity/ | 7df783d5269a | curl | no fix listed | 1 |
| felipecs8/ | 29e06c9c6385 | curl | no fix listed | 1 |
| filebrowser/ | dbac07403040 | curl | 8.22.0-r0 | 1 |
| firefart/ | 0d6249906d8c | curl | no fix listed | 1 |
| fireflyiii/ | ae69fdd95cde | curl | no fix listed | 1 |
| fiware/ | d551a13e8278 | curl | no fix listed | 1 |
| flanksource/ | 689687a7cf95 | curl | no fix listed | 1 |
| flashcatcloud/ | 42e6ab16472e | curl | no fix listed | 1 |
| fluent/ | a52221a2a3eb | curl | no fix listed | 1 |
| fluent/ | a941bdd5ca55 | curl | no fix listed | 1 |
| fluent/ | ca08b7d2df5b | curl | no fix listed | 1 |
| fluent/ | e76397ef3983 | curl | no fix listed | 1 |
| folioci/ | f0655a6a08fd | curl | 8.22.0-r0 | 1 |
| fosrl/ | 83a55f933b4d | curl | no fix listed | 1 |
| fosrl/ | c32ad797ab96 | curl | 8.22.0-r0 | 1 |
| frankescobar/ | dc171ec796d5 | curl | no fix listed | 1 |
| galaxy/ | e50a890e24c9 | curl | no fix listed | 1 |
| garethgeorge/ | b85297975428 | curl | 8.22.0-r0 | 1 |
| geonode/ | 435cbc5f3f05 | curl | 8.22.0-r0 | 1 |
| geoservercloud/ | de0b20bd2a43 | curl | no fix listed | 1 |
| geoservercloud/ | b04ed89b5d2b | curl | no fix listed | 1 |
| geoservercloud/ | 318254b52f96 | curl | no fix listed | 1 |
| geoservercloud/ | 4f077124f591 | curl | no fix listed | 1 |
| geoservercloud/ | 4f91e3048ac8 | curl | no fix listed | 1 |
| geoservercloud/ | 299f0d6232d1 | curl | no fix listed | 1 |
| geoservercloud/ | 5164f687ce4d | curl | no fix listed | 1 |
| getsentry/ | ba7bf9163219 | curl | no fix listed | 1 |
| ghostfolio/ | e3c6ab53e49b | curl | no fix listed | 1 |
| gitea/ | 7940221bcfc9 | curl | 8.22.0-r0 | 1 |
| gitea/ | b5c35d6bdbb9 | curl | 8.22.0-r0 | 1 |
| gitea/ | c2a169c5e998 | curl | 8.22.0-r0 | 1 |
| gitea/ | 1c17ecaead42 | curl | 8.22.0-r0 | 1 |
| gitea/ | 34e3f6b75f5c | curl | 8.22.0-r0 | 1 |
| gitea/ | 7d13848af126 | curl | 8.22.0-r0 | 1 |