StackRadar

CVE-2026-19931

Critical

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,791
of 17,792 indexed, latest versions
Container images
1,599
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,791 of 17,792 indexed charts deploy, on 1,599 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 moreno fix listed1,248
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0351
OSV records
ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931CGA-4wpj-77jq-67v6ECHO-5bd0-12f6-d009
Also known as
CGA-h86j-p398-8x8h
Trending
Rank 27 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,791 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,599 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
n8nio/n8n:2.38.45d9f0cc5672b
curl@8.21.0-r0
8.22.0-r0
1
n8nio/n8n:2.39.5cfa04788a34a
curl@8.21.0-r0
8.22.0-r0
1
n8nio/n8n:2.36.8cfe2704ff858
curl@8.21.0-r0
8.22.0-r0
1
netbirdio/dashboard:v2.91.0aae926912ca4
curl@8.21.0-r0
8.22.0-r0
1
netboxcommunity/netbox:v3.2.83d652dca5351
curl@7.81.0-1ubuntu1.3
no fix listed
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
curl@8.18.0-1ubuntu2.3
no fix listed
1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
curl@8.17.0-r1
8.22.0-r0
1
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
curl@7.81.0-1ubuntu1.25
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
curl@8.14.1-2+deb13u2
no fix listed
1
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
curl@8.14.1-2
no fix listed
1
nginxinc/nginx-unprivileged:latest4210a3296e7c
curl@8.14.1-2+deb13u4
no fix listed
1
nginxinc/nginx-unprivileged:1.31.2-alpine3.236320020c7da8
curl@8.19.0-r0
8.22.0-r0
1
nginxinc/nginx-unprivileged:1.31.4-alpine-otelb37d9945be77
curl@8.21.0-r0
8.22.0-r0
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
curl@8.14.1-2+deb13u2
no fix listed
1
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
curl@8.17.0-r1
8.22.0-r0
1
nginxinc/nginx-unprivileged:1.31.3-alpinef972e5322b97
curl@8.21.0-r0
8.22.0-r0
1
nirmalnaveen/supermario:latest8541a39162f3
curl@7.88.1-10+deb12u4
no fix listed
1
nocodb/nocodb:latest4b760f0d2547
curl@8.20.0-r0
8.22.0-r0
1
nodered/node-red:5.0.410f40d0a83e7
curl@8.21.0-r0
8.22.0-r0
1
nodered/node-red:4.1.10-minimald73ae167cb9b
curl@8.17.0-r1
8.22.0-r0
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
curl@8.14.1-2+deb13u4
no fix listed
1
novosga/novosga:latest34b9acbe6e51
curl@8.17.0-r1
8.22.0-r0
1
obolnetwork/helios:e10e753cb7e97d39d46
curl@8.5.0-2ubuntu10.6
no fix listed
1
octoboxio/octobox:latestd909041c46eb
curl@8.17.0-r1
8.22.0-r0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
curl@7.88.1-10+deb12u14
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
curl@7.88.1-10+deb12u6
no fix listed
1
oled01/automx2:2025.1.105d3e398e675
curl@7.88.1-10+deb12u12
no fix listed
1
oled01/db-backup:0.1.06302fd2b5333
curl@7.81.0-1ubuntu1.6
no fix listed
1
olvid/bot-daemon:2.0.1e0e6b165d879
curl@8.5.0-2ubuntu10.8
no fix listed
1
omecproject/c3po-hssdb:master-latest28a90cc26716
curl@7.68.0-1ubuntu2.6
no fix listed
1
opea/chatqna:1.038c51b791efa
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codegen:1.058f91683892d
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
curl@7.88.1-10+deb12u5
no fix listed
1
opea/codetrans:1.0e2436483b73d
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
curl@7.88.1-10+deb12u5
no fix listed
1
opea/docsum:1.03eaa91849512
curl@7.88.1-10+deb12u7
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
curl@7.88.1-10+deb12u5
no fix listed
1
opea/speecht5:1.0249afad3d268
curl@7.88.1-10+deb12u7
no fix listed
1
openaev/platform:3.260904.00a12ce8b3db9
curl@8.5.0-2ubuntu10.12
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
curl@7.88.1-10+deb12u8
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
curl@8.5.0-2ubuntu10.6
no fix listed
1
opencloudeu/opencloud:7.2.46d992ccc5f1c
curl@8.21.0-r0
8.22.0-r0
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
curl@7.88.1-10+deb12u7
no fix listed
1
opendatacube/explorer:latest120457ffcd69
curl@8.5.0-2ubuntu10.6
no fix listed
1
opendatacube/wps:latest80df355a660b
curl@7.81.0-1ubuntu1.20
no fix listed
1
openelevation/open-elevation:latest82fb21612e86
curl@7.68.0-1ubuntu2.5
no fix listed
1
openhab/openhab:5.2.1bfd4a60e90da
curl@8.14.1-2+deb13u4
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
curl@7.68.0-1ubuntu2.13
no fix listed
1
openmined/syft-backend:0.9.5b72f74a68b32
curl@8.12.0-r1
8.22.0-r0
1
opennode/waldur-homeport:8.1.2a8b5b4777027
curl@8.21.0-r0
8.22.0-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.