CVE-2026-18924
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.009
- 58th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,933
- of 17,790 indexed, latest versions
- Container images
- 1,747
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,933 of 17,790 indexed charts deploy, on 1,747 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+107 more | 1:8.14.1-2+deb13u3+e2 | 1,387 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 360 |
- OSV records
- ALPINE-CVE-2026-18924DEBIAN-CVE-2026-18924UBUNTU-CVE-2026-18924CGA-wm55-j9f4-wjrvECHO-0181-5c6a-1eed
- Also known as
- CGA-xmww-h2xq-268q
- Trending
- Rank 28 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,933 by stars
Container images carrying it
1,747 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 983261ecc40a | curl | 8.22.0-r0 | 1 |
| library/ | ac978b783657 | curl | no fix listed | 1 |
| library/ | 13ba145cba2f | curl | 8.22.0-r0 | 1 |
| library/ | 834468128c76 | curl | 8.22.0-r0 | 1 |
| library/ | b095ff3248c6 | curl | no fix listed | 1 |
| library/ | ae605bfcda05 | curl | no fix listed | 1 |
| library/ | 2817ad50b5c5 | curl | no fix listed | 1 |
| library/ | 3ef33f2e220b | curl | 8.22.0-r0 | 1 |
| library/ | 28f7931ecbcb | curl | no fix listed | 1 |
| library/ | 1f79c73404fb | curl | no fix listed | 1 |
| library/ | 85f00967bcc6 | curl | no fix listed | 1 |
| library/ | 2cc40b15dff8 | curl | no fix listed | 1 |
| library/ | 310b9fc03b06 | curl | no fix listed | 1 |
| library/ | 332c6d416808 | curl | no fix listed | 1 |
| library/ | 88c2ec10c7f2 | curl | no fix listed | 1 |
| library/ | fdc73b3249c1 | curl | no fix listed | 1 |
| library/ | 2461f02672b3 | curl | no fix listed | 1 |
| library/ | 512690a56605 | curl | no fix listed | 1 |
| library/ | 1ae8051591a5 | curl | no fix listed | 1 |
| library/ | 571eb4514977 | curl | no fix listed | 1 |
| library/ | 695a8063ff10 | curl | no fix listed | 1 |
| library/ | 6ce2bf22499b | curl | no fix listed | 1 |
| library/ | 8812029260b5 | curl | no fix listed | 1 |
| library/ | b0f9fc41ed79 | curl | no fix listed | 1 |
| library/ | f75e48af0598 | curl | no fix listed | 1 |
| library/ | 0172f1c538e7 | curl | no fix listed | 1 |
| library/ | 04c0fc150f3a | curl | no fix listed | 1 |
| library/ | c5781ba340ef | curl | no fix listed | 1 |
| library/ | e2e2031c15be | curl | no fix listed | 1 |
| library/ | 712e407b20ea | curl | no fix listed | 1 |
| library/ | 17a4f64e9cf5 | curl | no fix listed | 1 |
| library/ | 2415789e1602 | curl | no fix listed | 1 |
| library/ | 8e6bdd396496 | curl | no fix listed | 1 |
| library/ | 0032d2ca20db | curl | no fix listed | 1 |
| library/ | 02a0cc7939f5 | curl | no fix listed | 1 |
| library/ | 05678ae4e5e1 | curl | no fix listed | 1 |
| library/ | 3b6c281e1c08 | curl | no fix listed | 1 |
| library/ | 3d0e6df9fd5b | curl | no fix listed | 1 |
| library/ | 406a4fdca9fc | curl | no fix listed | 1 |
| library/ | 50cae5081ab4 | curl | no fix listed | 1 |
| library/ | 646902910d6a | curl | no fix listed | 1 |
| library/ | 699d652ed674 | curl | no fix listed | 1 |
| library/ | 6ca49afbcb2b | curl | no fix listed | 1 |
| library/ | 6ede2806c78e | curl | no fix listed | 1 |
| library/ | 71a63fc2438e | curl | no fix listed | 1 |
| library/ | 7c81758cb295 | curl | no fix listed | 1 |
| library/ | 84c4a18b60a0 | curl | no fix listed | 1 |
| library/ | 88785f6f665a | curl | no fix listed | 1 |
| library/ | 9cb28f7291d9 | curl | no fix listed | 1 |
| library/ | ae1cf99fa7bf | curl | no fix listed | 1 |