CVE-2026-18924
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.009
- 58th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,933
- of 17,790 indexed, latest versions
- Container images
- 1,747
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,933 of 17,790 indexed charts deploy, on 1,747 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+107 more | 1:8.14.1-2+deb13u3+e2 | 1,387 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 360 |
- OSV records
- ALPINE-CVE-2026-18924DEBIAN-CVE-2026-18924UBUNTU-CVE-2026-18924CGA-wm55-j9f4-wjrvECHO-0181-5c6a-1eed
- Also known as
- CGA-xmww-h2xq-268q
- Trending
- Rank 28 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,933 by stars
Container images carrying it
1,747 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | d23ec07162ca | curl | no fix listed | 1 |
| library/ | dca8d11fe467 | curl | no fix listed | 1 |
| library/ | 6d1b2bd0947e | curl | 8.22.0-r0 | 1 |
| library/ | 588609d76b21 | curl | no fix listed | 1 |
| library/ | 8418c398d767 | curl | no fix listed | 1 |
| library/ | b7faa1653c39 | curl | no fix listed | 1 |
| library/ | b97df9e0e1ee | curl | no fix listed | 1 |
| library/ | de4ad9389386 | curl | no fix listed | 1 |
| library/ | 09369da6b103 | curl | no fix listed | 1 |
| library/ | 1881968aff6f | curl | no fix listed | 1 |
| library/ | 2f07d83bf561 | curl | 8.22.0-r0 | 1 |
| library/ | 4a73073bd557 | curl | 8.22.0-r0 | 1 |
| library/ | 5616878291a2 | curl | 8.22.0-r0 | 1 |
| library/ | 6784fb0834aa | curl | no fix listed | 1 |
| library/ | 67f9a4f10d14 | curl | no fix listed | 1 |
| library/ | 9ff236ed47fe | curl | no fix listed | 1 |
| library/ | a53fc6c27208 | curl | no fix listed | 1 |
| library/ | a8b39bd9cf0f | curl | 8.22.0-r0 | 1 |
| library/ | fb197595ebe7 | curl | no fix listed | 1 |
| library/ | 8f693eaa7e0a | curl | no fix listed | 1 |
| library/ | f5d1cc40abc1 | curl | no fix listed | 1 |
| library/ | 22a4c414bb8e | curl | 8.22.0-r0 | 1 |
| library/ | 59fa733c9af6 | curl | no fix listed | 1 |
| library/ | 54451ecb8ab3 | curl | 8.22.0-r0 | 1 |
| library/ | 9a8afca54e78 | curl | 8.22.0-r0 | 1 |
| library/ | 70c9cc675605 | curl | no fix listed | 1 |
| library/ | d41127070014 | curl | no fix listed | 1 |
| library/ | da5aee29682d | curl | no fix listed | 1 |
| library/ | 04ac44a2595b | curl | no fix listed | 1 |
| library/ | 0842dcd4c8f8 | curl | no fix listed | 1 |
| library/ | ef9723cf4fe4 | curl | no fix listed | 1 |
| library/ | 507a3eecf809 | curl | no fix listed | 1 |
| library/ | 9e1d2afa6898 | curl | no fix listed | 1 |
| library/ | 8ae66efb09a2 | curl | no fix listed | 1 |
| library/ | ad4a8bae2eb4 | curl | no fix listed | 1 |
| library/ | f73396626d2f | curl | no fix listed | 1 |
| library/ | 56490ac14a31 | curl | no fix listed | 1 |
| library/ | 55d1e5b2e601 | curl | no fix listed | 1 |
| library/ | cab8944a33a1 | curl | no fix listed | 1 |
| library/ | dfa9ba46d14b | curl | no fix listed | 1 |
| librenms/ | 8194a4a9ff49 | curl | 8.22.0-r0 | 1 |
| lightbend/ | b0c9894ac8dd | curl | no fix listed | 1 |
| linuxserver/ | a20fb11a440d | curl | 8.22.0-r0 | 1 |
| linuxserver/ | 2ebf97852661 | curl | 8.22.0-r0 | 1 |
| linuxserver/ | a847b5b2d860 | curl | no fix listed | 1 |
| linuxserver/ | 241009026e6f | curl | no fix listed | 1 |
| linuxserver/ | 938810eca3d3 | curl | no fix listed | 1 |
| linuxserver/ | 45c5fe102ff3 | curl | no fix listed | 1 |
| linuxserver/ | a5e43a05ae79 | curl | no fix listed | 1 |
| linuxserver/ | b801bbcf6386 | curl | no fix listed | 1 |