CVE-2026-18924
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.009
- 58th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,933
- of 17,790 indexed, latest versions
- Container images
- 1,747
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,933 of 17,790 indexed charts deploy, on 1,747 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+107 more | 1:8.14.1-2+deb13u3+e2 | 1,387 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 360 |
- OSV records
- ALPINE-CVE-2026-18924DEBIAN-CVE-2026-18924UBUNTU-CVE-2026-18924CGA-wm55-j9f4-wjrvECHO-0181-5c6a-1eed
- Also known as
- CGA-xmww-h2xq-268q
- Trending
- Rank 28 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,933 by stars
Container images carrying it
1,747 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| zimengxiong/ | 242629350b06 | curl | 8.22.0-r0 | 1 |
| zimengxiong/ | 4ec5b20c0303 | curl | 8.22.0-r0 | 1 |
| zooproject/ | 9a507cb7e2dd | curl | no fix listed | 1 |
| gcr.io/ | 6efe04ba4e06 | curl | no fix listed | 1 |
| gcr.io/ | de6ff0f1a854 | curl | no fix listed | 1 |
| gcr.io/ | 5f5918f843a4 | curl | no fix listed | 1 |
| gcr.io/ | 809338a69bd5 | curl | no fix listed | 1 |
| gcr.io/ | 6d35276c2562 | curl | 8.22.0-r0 | 1 |
| gcr.io/ | 10f4dbc8eeeb | curl | no fix listed | 1 |
| gcr.io/ | cb5c1bddd1b5 | curl | no fix listed | 1 |
| gcr.io/ | 5ea7b7f3632a | curl | no fix listed | 1 |
| gcr.io/ | c552478f8f11 | curl | no fix listed | 1 |
| gcr.io/ | 8f9ff98fdbef | curl | no fix listed | 1 |
| gcr.io/ | 9538fabe49fd | curl | no fix listed | 1 |
| gcr.io/ | ec6f9ea5757b | curl | no fix listed | 1 |
| gcr.io/ | 8d4576f7b98f | curl | no fix listed | 1 |
| gcr.io/ | 9bcfd2abc361 | curl | no fix listed | 1 |
| ghcr.io/ | 7930061993f7 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | c4c1938a973b | curl | no fix listed | 1 |
| ghcr.io/ | 779759172676 | curl | no fix listed | 1 |
| ghcr.io/ | 4c28334f3c79 | curl | no fix listed | 1 |
| ghcr.io/ | cc9a028d9c43 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 459010a02aff | curl | no fix listed | 1 |
| ghcr.io/ | d110504d551d | curl | no fix listed | 1 |
| ghcr.io/ | 18689773150d | curl | no fix listed | 1 |
| ghcr.io/ | 71be54e99608 | curl | no fix listed | 1 |
| ghcr.io/ | d332ae2410f8 | curl | no fix listed | 1 |
| ghcr.io/ | 13e267ad7d94 | curl | no fix listed | 1 |
| ghcr.io/ | 2d4d776f6362 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | e9c2ce635b89 | curl | no fix listed | 1 |
| ghcr.io/ | f527d10769ac | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | f9104080d9a7 | curl | no fix listed | 1 |
| ghcr.io/ | 4a2824296412 | curl | no fix listed | 1 |
| ghcr.io/ | 20518335f9f9 | curl | no fix listed | 1 |
| ghcr.io/ | 67ffb0309acb | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 70d9d1b78d39 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | cb5f24732197 | curl | no fix listed | 1 |
| ghcr.io/ | fcbab3a24880 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 5889bea38e56 | curl | no fix listed | 1 |
| ghcr.io/ | 10b7945d4f09 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 8766ba08bf1a | curl | no fix listed | 1 |
| ghcr.io/ | 0379598e9ad2 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 8eb6e492fe3c | curl | no fix listed | 1 |
| ghcr.io/ | 1aba0ffe55ea | curl | no fix listed | 1 |
| ghcr.io/ | ab63d26a8a2c | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 72f35584026d | curl | no fix listed | 1 |
| ghcr.io/ | 16759fa523f8 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | b6373349a301 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | dd1df8408daf | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 6fde1edc0983 | curl | no fix listed | 1 |