StackRadar

CVE-2026-19931

Critical

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.012
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,801
of 17,781 indexed, latest versions
Container images
1,613
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,801 of 17,781 indexed charts deploy, on 1,613 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 moreno fix listed1,268
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+3 more8.22.0-r0345
OSV records
ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931ECHO-5bd0-12f6-d009
Trending
Rank 20 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,801 by stars
ChartLatestAffected imagesRadar Score
kangalkangal2.3.11 of 2See more

kangal kangal 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
swaggerapi/swagger-ui:latest9ae209e3791e
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

370
web-chartkbt-ktcloudlab0.1.01 of 1See more

web-chart kbt-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

5,508
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

5,789
app-componentkeltio-helm-chartsVerified publisher3.14.01 of 1See more

app-component keltio-helm-charts 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

5,228
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
curl@7.68.0-1ubuntu2.20
no fix listed

Open the chart page →

5,264
netbirdkitstream-netbird0.7.01 of 3See more

netbird kitstream-netbird 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
netbirdio/dashboard:v2.91.0aae926912ca4
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

1,291
glpikitsune-itopsVerified publisher1.0.71 of 3See more

glpi kitsune-itops 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
glpi/glpi:latest4b681082a79e
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,802
powerdns-recursorklicktippVerified publisher0.4.101 of 1See more

powerdns-recursor klicktipp 0.4.10

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
powerdns/pdns-recursor-54:5.4.533aadc74a8d6
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,873
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

20,403
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
curl@7.81.0-1ubuntu1.24
no fix listed

Open the chart page →

9,858
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
curl@7.68.0-1ubuntu2.13
no fix listed

Open the chart page →

7,710
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
curl@7.68.0-1ubuntu2.7
no fix listed

Open the chart page →

12,422
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
curl@7.68.0-1ubuntu2.6
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
curl@7.68.0-1ubuntu2.5
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
curl@7.68.0-1ubuntu2.6
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
curl@7.68.0-1ubuntu2.6
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
curl@7.68.0-1ubuntu2.6
no fix listed

Open the chart page →

113,791
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/caddy:2-alpine5f5c8640aae0
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

5,654
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

3,544
api-docslabs64io-helm-chartsVerified publisher0.7.21 of 1See more

api-docs labs64io-helm-charts 0.7.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
swaggerapi/swagger-ui:v5.32.143d9316996884
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

370
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

3,980
lgtm-stacklgtm-stackVerified publisher0.1.31 of 8See more

lgtm-stack lgtm-stack 0.1.3

1 of the 8 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
grafana/grafana:13.1.0121a7a9ece6d
curl@8.20.0-r1
8.22.0-r0

Open the chart page →

5,576
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

35,050
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
curl@8.5.0-2ubuntu10.6
no fix listed

Open the chart page →

7,874
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

7,201
plexluiscajl1.0.11 of 2See more

plex luiscajl 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
curl@8.18.0-1ubuntu2.4
no fix listed

Open the chart page →

810
voice-biometricslumenvox2.0.11 of 26See more

voice-biometrics lumenvox 2.0.1

1 of the 26 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
lumenvox/cloud-binary-storage:2.0.053decadc102d
curl@7.68.0-1ubuntu2.7
no fix listed

Open the chart page →

70,741
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

6,136
radarrm0nsterrr-radarrVerified publisher3.6.31 of 1See more

radarr m0nsterrr-radarr 3.6.3

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/home-operations/radarr:6.4.30ebb4ae26ee9
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

480
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
glarad/mcp-management-portal-clr:0.6.8807e453354a7
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

6,929
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

2,753
medusamedusaVerified publisher1.3.81 of 1See more

medusa medusa 1.3.8

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

977
metrics-server-exportermetrics-server-exporterVerified publisher2.4.01 of 1See more

metrics-server-exporter metrics-server-exporter 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
mrnim94/metrics-server-exporter:v2.4.086c4807a4bca
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,272
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

13,738
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

7,527
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

1,879
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
curl@7.81.0-1ubuntu1.19
no fix listed

Open the chart page →

3,689
clowder2ncsaVerified publisher1.9.72 of 12See more

clowder2 ncsa 1.9.7

2 of the 12 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
curl@7.88.1-10+deb12u5
no fix listed
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

37,373
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

14,250
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

5,039
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
curl@7.88.1-10
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

14,838
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
curl@8.5.0-2ubuntu10.8
no fix listed

Open the chart page →

5,779
opentelemetry-demoopentelemetry-helmVerified publisher0.41.13 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

3 of the 34 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
grafana/grafana:13.1.0121a7a9ece6d
curl@8.20.0-r1
8.22.0-r0
ghcr.io/open-telemetry/demo:3.0.0-telemetry-docs3519858704e7
curl@8.19.0-r0
8.22.0-r0
ghcr.io/open-telemetry/demo:3.0.0-quote6bc8f7f6809e
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

22,420
opikopikOfficialVerified publisher2.2.594 of 13See more

opik opik 2.2.59

4 of the 13 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.0862d86046bbc
curl@8.17.0-r1
8.22.0-r0
library/zookeeper:3.9.4dfa9ba46d14b
curl@7.81.0-1ubuntu1.21
no fix listed
ghcr.io/comet-ml/opik/opik-frontend:2.2.59bc2f49e9bb3e
curl@8.19.0-r0
8.22.0-r0
ghcr.io/comet-ml/opik/opik-python-backend:2.2.59269d0e55ea97
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

14,334
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
curl@7.81.0-1ubuntu1.25
no fix listed
shaowenchen/ops-server:latest315444f703f4
curl@7.81.0-1ubuntu1.20
no fix listed

Open the chart page →

8,939
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

3,681
prowlarrpanzer1119Verified publisher0.4.181 of 2See more

prowlarr panzer1119 0.4.18

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
linuxserver/prowlarr:2.4.0.5397-ls149a46d0ce0a823
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,001
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

8,489

Container images carrying it

1,613 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/grafana:13.1.17cb8c64c4d57
curl@8.21.0-r0
8.22.0-r0
3
guacamole/guacamole:1.6.0f344085e618b
curl@8.5.0-2ubuntu10.6
no fix listed
3
jacobalberty/unifi:v10.0.162896c0ab82d33
curl@7.68.0-1ubuntu2.25
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
curl@7.88.1-10+deb12u5
no fix listed
3
library/node:ltsbe23f54a88d3
curl@7.88.1-10+deb12u15
no fix listed
3
localstack/localstack-pro:latest4aef81c53168
curl@8.14.1-2+deb13u4
no fix listed
3
natsio/nats-box:0.19.7ffce8bd10338
curl@8.19.0-r0
8.22.0-r0
3
selenium/hub:3.141.5902f251d48d5f
curl@7.68.0-1ubuntu2.7
no fix listed
3
vaultwarden/server:1.37.1ebdfe70701c6
curl@8.14.1-2+deb13u4
no fix listed
3
xenondb/percona:5.7.330e26872a2b67
curl@7.68.0-1ubuntu2.5
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
curl@7.88.1-10
no fix listed
3
quay.io/argoproj/argocd:v3.5.2e2aadfae709d
curl@8.18.0-1ubuntu2.4
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
curl@7.88.1-10+deb12u7
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
curl@7.81.0-1ubuntu1.7
no fix listed
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
curl@8.5.0-2ubuntu10.11
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
curl@8.5.0-2ubuntu10.10
no fix listed
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
curl@7.81.0-1ubuntu1.10
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
curl@7.88.1-10+deb12u14
no fix listed
3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
curl@8.17.0-r1
8.22.0-r0
3
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
curl@8.21.0-r0
8.22.0-r0
3
alpine/git:latest4f9488b7295b
curl@8.21.0-r0
8.22.0-r0
2
alpine/k8s:1.32.12048f8d9c8cc7
curl@8.18.0-r0
8.22.0-r0
2
alpine/kubectl:1.35.49ccd82364762
curl@8.17.0-r1
8.22.0-r0
2
alpine/kubectl:1.35.2ec8f734b0a10
curl@8.17.0-r1
8.22.0-r0
2
apache/nifi-registry:1.26.07cdfd8deec92
curl@7.81.0-1ubuntu1.16
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
curl@8.5.0-2ubuntu10.6
no fix listed
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
curl@8.5.0-2ubuntu10.1
no fix listed
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
curl@7.88.1-10+deb12u12
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
curl@7.88.1-10+deb12u12
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
curl@8.14.1-2+deb13u4
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
curl@7.88.1-10+deb12u5
no fix listed
2
clamav/clamav:1.4.3_base629a3050df6a
curl@8.17.0-r1
8.22.0-r0
2
cribl/cribl:4.19.2044f9a5fac9a
curl@8.5.0-2ubuntu10.12
no fix listed
2
dunglas/mercure:v0:v0.24.2916834e49961
curl@8.17.0-r1
8.22.0-r0
2
eqalpha/keydb:latest6537505c4235
curl@7.68.0-1ubuntu2.20
no fix listed
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
curl@7.68.0-1ubuntu2.20
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
curl@8.14.1-2+deb13u2
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
curl@8.14.1-2+deb13u2
no fix listed
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
curl@7.68.0-1ubuntu2.7
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
curl@7.68.0-1ubuntu2.7
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
curl@7.68.0-1ubuntu2.7
no fix listed
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
curl@7.68.0-1ubuntu2.7
no fix listed
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
curl@7.68.0-1ubuntu2.7
no fix listed
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
curl@7.68.0-1ubuntu2.7
no fix listed
2
gisaia/agate:0.18.198213fa403ae
curl@8.21.0-r0
8.22.0-r0
2
gisaia/airs:0.18.15abfe00317bf
curl@8.21.0-r0
8.22.0-r0
2
gisaia/aproc-service:0.18.1ac6564921994
curl@8.21.0-r0
8.22.0-r0
2
gisaia/arlas-fam-wui:0.18.13700dcaf7a75
curl@8.20.0-r0
8.22.0-r0
2
gisaia/arlas-wui:28.0.3b83b3e067173
curl@8.19.0-r0
8.22.0-r0
2
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
curl@8.19.0-r0
8.22.0-r0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.