CVE-2026-19931
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.012
- 65th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,814
- of 17,790 indexed, latest versions
- Container images
- 1,636
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,814 of 17,790 indexed charts deploy, on 1,636 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 more | no fix listed | 1,276 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 360 |
- OSV records
- ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931CGA-4wpj-77jq-67v6ECHO-5bd0-12f6-d009
- Also known as
- CGA-h86j-p398-8x8h
- Trending
- Rank 27 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,814 by stars
Container images carrying it
1,636 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| istio/ | 72f25a55f078 | curl | no fix listed | 1 |
| istio/ | 8f92fc1b6592 | curl | no fix listed | 1 |
| istio/ | 328b237e4fb1 | curl | no fix listed | 1 |
| istio/ | 0a7f02b2c7c9 | curl | no fix listed | 1 |
| istio/ | ab34c4740f44 | curl | no fix listed | 1 |
| istio/ | ce27c9ce43c8 | curl | no fix listed | 1 |
| istio/ | 6cfce8a071b9 | curl | no fix listed | 1 |
| istio/ | 70f9d1fe5fff | curl | no fix listed | 1 |
| istio/ | 325156535773 | curl | no fix listed | 1 |
| istio/ | 9c3d6a218181 | curl | no fix listed | 1 |
| istio/ | ac0284d75ec9 | curl | no fix listed | 1 |
| istio/ | ce9d87606701 | curl | no fix listed | 1 |
| istio/ | db08d6963975 | curl | no fix listed | 1 |
| istio/ | f8b0e412ac4a | curl | no fix listed | 1 |
| istio/ | df69c1a7af7c | curl | no fix listed | 1 |
| istio/ | 05f3972d80a9 | curl | no fix listed | 1 |
| itzg/ | 1c59f9631f3b | curl | no fix listed | 1 |
| itzg/ | 8672e335dbef | curl | no fix listed | 1 |
| itzg/ | e8640538dac5 | curl | no fix listed | 1 |
| ixsystems/ | 19c218455cd2 | curl | no fix listed | 1 |
| jaedb/ | 048cfbf58d57 | curl | no fix listed | 1 |
| jakowenko/ | b858bac9e32a | curl | no fix listed | 1 |
| jbtronics/ | 5db71f6db59d | curl | no fix listed | 1 |
| jedi132000/ | dc2a81e92f23 | curl | no fix listed | 1 |
| jellyfin/ | 1694ff069f0c | curl | no fix listed | 1 |
| jellyfin/ | 17285f9cce63 | curl | no fix listed | 1 |
| jellyfin/ | 17c3a8d9dddb | curl | no fix listed | 1 |
| jellyfin/ | 333b64771663 | curl | no fix listed | 1 |
| jellyfin/ | 79fb3d73a3e9 | curl | no fix listed | 1 |
| jellyfin/ | 7ae36aab93ef | curl | no fix listed | 1 |
| jellyfin/ | 96b09723b22f | curl | no fix listed | 1 |
| jenkins/ | 95313257a8cd | curl | no fix listed | 1 |
| jenkins/ | de4fea113221 | curl | no fix listed | 1 |
| jertel/ | 3cbf63f9b7dc | curl | no fix listed | 1 |
| jesec/ | c887dad96b40 | curl | 8.22.0-r0 | 1 |
| jhipster/ | 7184525acd4d | curl | no fix listed | 1 |
| jhonbrownn/ | 6936e4f1caeb | curl | 8.22.0-r0 | 1 |
| jhoncytech/ | 18c3ca1f411e | curl | no fix listed | 1 |
| jingking/ | 43e74ab234e1 | curl | no fix listed | 1 |
| jitesoft/ | 9996dd28914f | curl | 8.22.0-r0 | 1 |
| jordan/ | f75025fe8ea8 | curl | no fix listed | 1 |
| josh5/ | 4d49c4816260 | curl | no fix listed | 1 |
| juicedata/ | 95008ba63318 | curl | no fix listed | 1 |
| jupyterhub/ | 3974ba945e65 | curl | no fix listed | 1 |
| jupyterhub/ | b6b4a1a34bf0 | curl | no fix listed | 1 |
| jupyterhub/ | e4770285aaf7 | curl | no fix listed | 1 |
| jupyterhub/ | e3e6f3051df8 | curl | no fix listed | 1 |
| jupyterjsc/ | aea53b13f235 | curl | 8.22.0-r0 | 1 |
| kafkace/ | 7adc206bf5a4 | curl | no fix listed | 1 |
| kafkakraft/ | 062d697db7e5 | curl | no fix listed | 1 |