CVE-2026-18924
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.009
- 58th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,938
- of 17,787 indexed, latest versions
- Container images
- 1,748
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,938 of 17,787 indexed charts deploy, on 1,748 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+107 more | 1:8.14.1-2+deb13u3+e2 | 1,383 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 365 |
- OSV records
- ALPINE-CVE-2026-18924DEBIAN-CVE-2026-18924UBUNTU-CVE-2026-18924CGA-wm55-j9f4-wjrvECHO-0181-5c6a-1eed
- Also known as
- CGA-xmww-h2xq-268q
- Trending
- Rank 22 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,938 by stars
Container images carrying it
1,748 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| aktosecurity/ | a6c1b933517f | curl | no fix listed | 1 |
| aktosecurity/ | 213aded7adc5 | curl | no fix listed | 1 |
| aktosecurity/ | 46ed5bcb04b2 | curl | no fix listed | 1 |
| aktosecurity/ | 5d4eab1c36b9 | curl | no fix listed | 1 |
| aktosecurity/ | 498e3e35ecc2 | curl | no fix listed | 1 |
| alazidis/ | 602d4f7f090c | curl | no fix listed | 1 |
| allegroai/ | 713ae38f7daf | curl | no fix listed | 1 |
| allegroai/ | 772827a01bb5 | curl | no fix listed | 1 |
| alpine/ | a1c44bab54d8 | curl | 8.22.0-r0 | 1 |
| alpine/ | 905a068da431 | curl | 8.22.0-r0 | 1 |
| alpine/ | 44ef4942e171 | curl | 8.22.0-r0 | 1 |
| alpine/ | b7a12c5ddf26 | curl | 8.22.0-r0 | 1 |
| alpine/ | d870622d0040 | curl | 8.22.0-r0 | 1 |
| alpine/ | 1ee9df6316d4 | curl | 8.22.0-r0 | 1 |
| alpine/ | 862d86046bbc | curl | 8.22.0-r0 | 1 |
| alpine/ | c4a11ae9a1cb | curl | 8.22.0-r0 | 1 |
| andrcuns/ | 43060f159f4c | curl | no fix listed | 1 |
| andrewgaul/ | 7dc1d34174a5 | curl | no fix listed | 1 |
| anguda/ | c435285fc241 | curl | no fix listed | 1 |
| antiantiops/ | eeff80a99d92 | curl | no fix listed | 1 |
| antrea/ | ee9686bcefb8 | curl | no fix listed | 1 |
| anujdatar/ | 685df04a643b | curl | no fix listed | 1 |
| apache/ | 0305c26f19ed | curl | no fix listed | 1 |
| apache/ | bae523439ee3 | curl | no fix listed | 1 |
| apache/ | 64e58748b6b9 | curl | no fix listed | 1 |
| apache/ | ce90bdc3d2af | curl | no fix listed | 1 |
| apache/ | e5560ad0b86e | curl | no fix listed | 1 |
| apache/ | a0d71b0e30a5 | curl | 8.22.0-r0 | 1 |
| apache/ | d173e7efe258 | curl | no fix listed | 1 |
| apache/ | 80136ae753ee | curl | no fix listed | 1 |
| apache/ | 75d48a62748f | curl | no fix listed | 1 |
| apache/ | a2bab1be574c | curl | no fix listed | 1 |
| apache/ | afa47bf1692a | curl | no fix listed | 1 |
| apache/ | 63b8e3e40742 | curl | no fix listed | 1 |
| apachepulsar/ | 16f9fdab3fa6 | curl | no fix listed | 1 |
| apachepulsar/ | 3b262ab7a7d9 | curl | no fix listed | 1 |
| apachepulsar/ | 9c9947de139d | curl | no fix listed | 1 |
| apachepulsar/ | d056c89b7131 | curl | no fix listed | 1 |
| apachepulsar/ | d538416d5afe | curl | no fix listed | 1 |
| apache/ | 76c176e8a0e4 | curl | no fix listed | 1 |
| apache/ | 434d8398f996 | curl | no fix listed | 1 |
| apache/ | c8fb51195444 | curl | no fix listed | 1 |
| apache/ | 133d35d2c263 | curl | no fix listed | 1 |
| apache/ | b4ec8c18d079 | curl | no fix listed | 1 |
| apache/ | 295f1dc87d98 | curl | no fix listed | 1 |
| apache/ | 80530f0308a5 | curl | no fix listed | 1 |
| apache/ | ab9467fd712c | curl | no fix listed | 1 |
| apache/ | 80072bb73dd3 | curl | no fix listed | 1 |
| apecloud/ | 8ac9947a2c84 | curl | no fix listed | 1 |
| appwrite/ | 1aaa70127114 | curl | 8.22.0-r0 | 1 |