StackRadar

CVE-2026-19931

Critical

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.012
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,819
of 17,787 indexed, latest versions
Container images
1,637
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,819 of 17,787 indexed charts deploy, on 1,637 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 moreno fix listed1,272
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0365
OSV records
ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931CGA-4wpj-77jq-67v6ECHO-5bd0-12f6-d009
Also known as
CGA-h86j-p398-8x8h
Trending
Rank 21 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,819 by stars
ChartLatestAffected imagesRadar Score
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

19,363
unboundunbound-helmchartVerified publisher0.2.21 of 1See more

unbound unbound-helmchart 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,495
athens-proxyvolker-raschekVerified publisher2.0.31 of 1See more

athens-proxy volker-raschek 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
gomods/athens:v0.17.10f61d1e62359
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,040
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
curl@8.5.0-2ubuntu10.6
no fix listed

Open the chart page →

2,996
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
curl@7.88.1-10+deb12u4
no fix listed

Open the chart page →

9,753
matrixzekker6Verified publisher3.30.01 of 4See more

matrix zekker6 3.30.0

1 of the 4 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.160.078de1d10bef0
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

5,568
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
curl@7.81.0-1ubuntu1.8
no fix listed

Open the chart page →

8,251
vaultwardenandrenarchyVerified publisher6.27.01 of 1See more

vaultwarden andrenarchy 6.27.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,756
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

1,245
limesurveyarea-42Verified publisher0.3.941 of 2See more

limesurvey area-42 0.3.94

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
adamzammit/limesurvey:7.1.0f48962e1528c
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,678
athens-proxyathens-chartsOfficialVerified publisher0.17.11 of 1See more

athens-proxy athens-charts 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
gomods/athens:v0.18.197cc113b34b0
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,299
bookstackbookstack-mgVerified publisher0.3.11 of 2See more

bookstack bookstack-mg 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
linuxserver/bookstack:26.05.202605282ebf97852661
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,896
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
curl@7.68.0-1ubuntu2.19
no fix listed

Open the chart page →

8,007
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
curl@8.18.0-1ubuntu2.3
no fix listed
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
curl@8.18.0-1ubuntu2.3
no fix listed
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
curl@8.18.0-1ubuntu2.3
no fix listed
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
curl@8.18.0-1ubuntu2.3
no fix listed
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
curl@8.18.0-1ubuntu2.3
no fix listed
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
curl@8.18.0-1ubuntu2.3
no fix listed
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
curl@8.18.0-1ubuntu2.3
no fix listed

Open the chart page →

10,819
collabora-codechrisingenhaag2.6.01 of 1See more

collabora-code chrisingenhaag 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
collabora/code:23.05.10.1.105299b452f7f
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

4,184
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

2,126
convertigoconvertigoOfficialVerified publisher8.4.33 of 5See more

convertigo convertigo 8.4.3

3 of the 5 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
curl@7.88.1-10+deb12u8
no fix listed
library/convertigo:8.4.3ae605bfcda05
curl@8.5.0-2ubuntu10.12
no fix listed
library/couchdb:3.4.22817ad50b5c5
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

17,475
cosmocosmo-platformOfficialVerified publisher0.20.02 of 10See more

cosmo cosmo-platform 0.20.0

2 of the 10 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
curl@7.88.1-10+deb12u12
no fix listed
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

27,984
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

9,348
defectdojodefectdojo1.9.521 of 4See more

defectdojo defectdojo 1.9.52

1 of the 4 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
defectdojo/defectdojo-django:3.3.100c597abdbb535
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,340
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
curl@8.5.0-2ubuntu10.5
no fix listed

Open the chart page →

4,194
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.4.25e594f5f09f6
curl@8.20.0-r1
8.22.0-r0

Open the chart page →

1,872
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine6d35276c2562
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

2,012
edgelessdbedgelesssysVerified publisher0.3.21 of 1See more

edgelessdb edgelesssys 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
curl@7.68.0-1ubuntu2.14
no fix listed

Open the chart page →

4,868
zabbix-agentfermosit0.0.51 of 1See more

zabbix-agent fermosit 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
curl@8.5.0-2ubuntu10.6
no fix listed

Open the chart page →

2,408
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
curl@7.68.0-1ubuntu2.20
no fix listed

Open the chart page →

5,302
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

4,563
flyte-coreflyte2.0.481 of 3See more

flyte-core flyte 2.0.48

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

1,179
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,729
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
curl@7.68.0-1ubuntu2.5
no fix listed

Open the chart page →

14,001
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
curl@7.68.0-1ubuntu2.12
no fix listed

Open the chart page →

9,666
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
curl@7.68.0-1ubuntu2.7
no fix listed

Open the chart page →

10,202
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
curl@7.68.0-1ubuntu2.7
no fix listed

Open the chart page →

10,676
gitlab-runnergitlab-jh0.92.11 of 1See more

gitlab-runner gitlab-jh 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

905
aegraviteeioVerified publisher3.0.21 of 1See more

ae graviteeio 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
graviteeio/ae-engine:3.0.24140932887e0
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,381
apimgraviteeioVerified publisher4.12.192 of 4See more

apim graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
curl@8.14.1-2+deb13u4
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,747
giteagroundhog2k0.16.31 of 1See more

gitea groundhog2k 0.16.3

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
gitea/gitea:1.27.387a67ee09d3a
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

536
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

1,820
jacketthalkeye0.1.31 of 1See more

jackett halkeye 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
linuxserver/jackett:latest609a1830692d
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

255
haproxyhaproxytechVerified publisher1.30.11 of 1See more

haproxy haproxytech 1.30.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
haproxytech/haproxy-alpine:3.4.37a3ef2dd8b5b
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

817
headscaleheadscaleVerified publisher1.0.191 of 3See more

headscale headscale 1.0.19

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
alpine/k8s:1.36.244ef4942e171
curl@8.20.0-r1
8.22.0-r0

Open the chart page →

3,396
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.21 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,245
home-assistanthome-assistantVerified publisher0.5.101 of 3See more

home-assistant home-assistant 0.5.10

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
curl@8.20.0-r1
8.22.0-r0

Open the chart page →

2,338
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

10,563
coreinstill-aiOfficialVerified publisher0.1.754 of 15See more

core instill-ai 0.1.75

4 of the 15 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
curl@8.14.1-2+deb13u2
no fix listed
instill/mgmt-backend:d0933d4ebe12f77a3f9
curl@8.14.1-2+deb13u2
no fix listed
instill/model-backend:611f0f2e980125e5ba5
curl@8.14.1-2+deb13u2
no fix listed
temporalio/admin-tools:1.28cfde8170c92f
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

30,920
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
curl@8.5.0-2ubuntu10.4
no fix listed

Open the chart page →

4,357
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
curl@8.5.0-2ubuntu10.11
no fix listed

Open the chart page →

4,546
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

4,634
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
curl@7.68.0-1ubuntu2.18
no fix listed

Open the chart page →

7,375
webdavk8s-webdavVerified publisher0.0.71 of 1See more

webdav k8s-webdav 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/httpd:2.4979c38c2228d
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,693

Container images carrying it

1,637 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/codegen:1.058f91683892d
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
curl@7.88.1-10+deb12u5
no fix listed
1
opea/codetrans:1.0e2436483b73d
curl@7.88.1-10+deb12u7
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
curl@7.88.1-10+deb12u5
no fix listed
1
opea/docsum:1.03eaa91849512
curl@7.88.1-10+deb12u7
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
curl@7.88.1-10+deb12u5
no fix listed
1
opea/speecht5:1.0249afad3d268
curl@7.88.1-10+deb12u7
no fix listed
1
openaev/platform:3.260904.00a12ce8b3db9
curl@8.5.0-2ubuntu10.12
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
curl@7.88.1-10+deb12u8
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
curl@8.5.0-2ubuntu10.6
no fix listed
1
opencloudeu/opencloud:7.2.46d992ccc5f1c
curl@8.21.0-r0
8.22.0-r0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
curl@7.88.1-10+deb12u14
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
curl@8.14.1-2+deb13u4
no fix listed
1
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
curl@7.88.1-10+deb12u14
no fix listed
1
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
curl@7.88.1-10+deb12u14
no fix listed
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
curl@7.88.1-10+deb12u7
no fix listed
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
curl@7.88.1-10+deb12u7
no fix listed
1
opencsghq/kubectl:latestb6d87e1048c2
curl@7.88.1-10+deb12u12
no fix listed
1
opencsghq/label-studio:v2.5.047e22aa71870
curl@8.14.1-2+deb13u4
no fix listed
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
curl@8.14.1-2+deb13u4
no fix listed
1
opendatacube/explorer:latest120457ffcd69
curl@8.5.0-2ubuntu10.6
no fix listed
1
opendatacube/wps:latest80df355a660b
curl@7.81.0-1ubuntu1.20
no fix listed
1
openelevation/open-elevation:latest82fb21612e86
curl@7.68.0-1ubuntu2.5
no fix listed
1
openhab/openhab:5.2.1bfd4a60e90da
curl@8.14.1-2+deb13u4
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
curl@7.68.0-1ubuntu2.13
no fix listed
1
openmined/syft-backend:0.9.5b72f74a68b32
curl@8.12.0-r1
8.22.0-r0
1
opennode/waldur-homeport:8.1.2a8b5b4777027
curl@8.21.0-r0
8.22.0-r0
1
opennode/waldur-mastermind:8.1.24c82b15d9042
curl@8.14.1-2+deb13u4
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
curl@7.88.1-10+deb12u12
no fix listed
1
openproject/openproject:17.8.0-slim48952034215d
curl@8.14.1-2+deb13u4
no fix listed
1
openresty/openresty:1.31.1.1-1-alpine-fatacd832254d9c
curl@8.19.0-r0
8.22.0-r0
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
curl@7.68.0-1ubuntu2.18
no fix listed
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
curl@7.68.0-1ubuntu2.20
no fix listed
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
curl@7.68.0-1ubuntu2.20
no fix listed
1
openvino/model_server:2025.2.11e7cd1d70cc1
curl@8.5.0-2ubuntu10.6
no fix listed
1
openvpn/openvpn-as:latest2253c10ec652
curl@8.5.0-2ubuntu10.11
no fix listed
1
owncloud/ocis:8.0.1b38fd8fdd58f
curl@8.17.0-r1
8.22.0-r0
1
owncloud/server:10.15.051d9b74fc2a8
curl@7.68.0-1ubuntu2.23
no fix listed
1
owncloud/server:10.16.274c53d341076
curl@7.81.0-1ubuntu1.24
no fix listed
1
owncloud/server:10.16.3b3f9efdcd7f7
curl@7.81.0-1ubuntu1.25
no fix listed
1
oxfordsemantic/rdfox:5.6db17910eb855
curl@7.68.0-1ubuntu2.7
no fix listed
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
curl@7.68.0-1ubuntu2.7
no fix listed
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
curl@8.14.1-2+deb13u3
no fix listed
1
penpotapp/backend:2.2.147853d9bb9dd
curl@7.81.0-1ubuntu1.18
no fix listed
1
penpotapp/exporter:2.2.15c835ffd87ab
curl@7.81.0-1ubuntu1.18
no fix listed
1
penpotapp/exporter:2.17.272a8061e8806
curl@8.18.0-1ubuntu2.4
no fix listed
1
penpotapp/frontend:2.17.294fa2864d8fc
curl@8.20.0-r0
8.22.0-r0
1
penpotapp/mcp:2.17.284f3f07ead11
curl@8.18.0-1ubuntu2.4
no fix listed
1
peterdavehello/tor-socks-proxy:latest0cc12d36d312
curl@8.17.0-r1
8.22.0-r0
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
curl@7.88.1-10+deb12u12
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.