CVE-2026-18924
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.009
- 58th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,933
- of 17,790 indexed, latest versions
- Container images
- 1,747
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,933 of 17,790 indexed charts deploy, on 1,747 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+107 more | 1:8.14.1-2+deb13u3+e2 | 1,387 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 360 |
- OSV records
- ALPINE-CVE-2026-18924DEBIAN-CVE-2026-18924UBUNTU-CVE-2026-18924CGA-wm55-j9f4-wjrvECHO-0181-5c6a-1eed
- Also known as
- CGA-xmww-h2xq-268q
- Trending
- Rank 28 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,933 by stars
Container images carrying it
1,747 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| somnathmore/ | bdfc06cad4ec | curl | no fix listed | 1 |
| sonatype/ | 56f8e1d24150 | curl | 8.22.0-r0 | 1 |
| sondresjo/ | f41e452800ff | curl | no fix listed | 1 |
| sonroyaalmerol/ | 3f60f3abe990 | curl | no fix listed | 1 |
| speckle/ | 092384dba45d | curl | no fix listed | 1 |
| speckle/ | 1f897ca906ea | curl | no fix listed | 1 |
| speckle/ | 52cad5e3293e | curl | no fix listed | 1 |
| speckle/ | 6dee853ba74a | curl | no fix listed | 1 |
| speckle/ | 787adcb20a3a | curl | no fix listed | 1 |
| speckle/ | 8f3c1ea153ba | curl | no fix listed | 1 |
| speckle/ | c102b087481a | curl | no fix listed | 1 |
| speckle/ | d3da0a84de98 | curl | no fix listed | 1 |
| sslhep/ | 1d12f943cec5 | curl | no fix listed | 1 |
| sslhep/ | e7aff7f97b89 | curl | no fix listed | 1 |
| sslhep/ | b01b8ee966ed | curl | no fix listed | 1 |
| sslhep/ | 0e4175a4e1eb | curl | no fix listed | 1 |
| sslhep/ | 671980005c57 | curl | no fix listed | 1 |
| sslhep/ | 596db2abdd09 | curl | no fix listed | 1 |
| sslhep/ | 54aaf1721d03 | curl | no fix listed | 1 |
| sslhep/ | 2cb88ceab5bb | curl | no fix listed | 1 |
| sslhep/ | c284442b44e3 | curl | no fix listed | 1 |
| stackstorm/ | 88235ba70cad | curl | no fix listed | 1 |
| stackstorm/ | 6f56d239d280 | curl | no fix listed | 1 |
| stackstorm/ | 33ecfda16608 | curl | no fix listed | 1 |
| stackstorm/ | 4e3f8c7ca52d | curl | no fix listed | 1 |
| stackstorm/ | f190a6212195 | curl | no fix listed | 1 |
| stackstorm/ | 259503496ff9 | curl | no fix listed | 1 |
| stackstorm/ | b1de2055c362 | curl | no fix listed | 1 |
| stackstorm/ | b1a338f64773 | curl | no fix listed | 1 |
| stackstorm/ | 1c8904a3bf67 | curl | no fix listed | 1 |
| stackstorm/ | 1bf35bfaf00c | curl | no fix listed | 1 |
| stackstorm/ | 09989a26c8b7 | curl | no fix listed | 1 |
| stackstorm/ | 19fdfffdbba8 | curl | no fix listed | 1 |
| stalwartlabs/ | 25001929f36a | curl | no fix listed | 1 |
| stalwartlabs/ | 388dcb75a707 | curl | no fix listed | 1 |
| stalwartlabs/ | 74ca4f7f6885 | curl | no fix listed | 1 |
| stardog/ | 2714e5c4b3c1 | curl | 8.22.0-r0 | 1 |
| stashapp/ | df744af5a0c9 | curl | 8.22.0-r0 | 1 |
| stashapp/ | a534c8afdf39 | curl | no fix listed | 1 |
| statcan/ | 3921305425b8 | curl | no fix listed | 1 |
| strangebee/ | a7f7b05fba24 | curl | no fix listed | 1 |
| streamnative/ | 11bceacec8fb | curl | no fix listed | 1 |
| structurizr/ | 4b5ffb5119c8 | curl | no fix listed | 1 |
| substratusai/ | 61695be635eb | curl | no fix listed | 1 |
| supabase/ | 49bfe526f1b4 | curl | no fix listed | 1 |
| supabase/ | f371b5f3f2ac | curl | 8.22.0-r0 | 1 |
| supabase/ | aa1c92c0cf32 | curl | no fix listed | 1 |
| supabase/ | d207e6e23ad3 | curl | no fix listed | 1 |
| supabase/ | d3aa0c86c7b3 | curl | no fix listed | 1 |
| supabase/ | 26d8070c55e9 | curl | no fix listed | 1 |