StackRadar

CVE-2026-19931

Critical

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,808
of 17,797 indexed, latest versions
Container images
1,620
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,808 of 17,797 indexed charts deploy, on 1,620 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 moreno fix listed1,269
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0351
OSV records
ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931CGA-4wpj-77jq-67v6ECHO-5bd0-12f6-d009
Also known as
CGA-h86j-p398-8x8h
Trending
Rank 35 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,808 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

7,714
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
curl@8.5.0-2ubuntu10.11
no fix listed
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

13,813
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,861
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,861
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

899
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,565
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,861
zoo-project-druzoo-projectOfficialVerified publisher0.10.42 of 6See more

zoo-project-dru zoo-project 0.10.4

2 of the 6 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
curl@8.21.0-r0
8.22.0-r0
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
curl@7.81.0-1ubuntu1.25
no fix listed

Open the chart page →

7,936

Container images carrying it

1,620 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
udhos/sqs-to-sns:2.0.15cf7979da82e1
curl@8.19.0-r0
8.22.0-r0
1
unitbuilds/velocity-workflow:1.0.0f85a34f5bb28
curl@8.5.0-2ubuntu10.13
no fix listed
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
curl@7.88.1-10+deb12u12
no fix listed
1
vaultwarden/server:1.35.443498a94b22f
curl@8.14.1-2+deb13u2
no fix listed
1
vaultwarden/server:1.34.384fd8a47f58d
curl@7.88.1-10+deb12u12
no fix listed
1
vaultwarden/server:1.35.79a8eec71f4a5
curl@8.14.1-2+deb13u2
no fix listed
1
vaultwarden/server:1.37.1-alpineb094afed4ed5
curl@8.21.0-r0
8.22.0-r0
1
vaultwarden/server:1.36.0-alpined3531610b486
curl@8.17.0-r1
8.22.0-r0
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
curl@7.88.1-10+deb12u12
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
curl@7.88.1-10+deb12u1
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
curl@7.88.1-10+deb12u1
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
curl@7.88.1-10+deb12u1
no fix listed
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
curl@8.14.1-2+deb13u4
no fix listed
1
wallarm/api-gateway:0.2.0a3d4d2f780e8
curl@7.88.1-10+deb12u14
no fix listed
1
wallarm/gateway-controller:0.4.09c6ed23e2f0e
curl@8.14.1-2+deb13u3
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
curl@7.68.0-1ubuntu2.18
no fix listed
1
wazuh/wazuh-manager:4.4.121994f40e0da
curl@7.68.0-1ubuntu2.18
no fix listed
1
weblate/weblate:2026.9.1.0990720d1737a
curl@8.18.0-1ubuntu2.4
no fix listed
1
wettyoss/wetty:latest7423b3d40ba2
curl@8.21.0-r0
8.22.0-r0
1
wiktorn/overpass-api:latest9bb5f4a9b54c
curl@7.88.1-10+deb12u15
no fix listed
1
wistefan/mvf:lateste0887302b2d8
curl@7.81.0-1ubuntu1.6
no fix listed
1
wolveix/satisfactory-server:v1.9.1199be1064b18
curl@7.81.0-1ubuntu1.19
no fix listed
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
curl@7.81.0-1ubuntu1.20
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
curl@7.81.0-1ubuntu1.16
no fix listed
1
wsjbr/duplistatus:1.4.25e594f5f09f6
curl@8.20.0-r1
8.22.0-r0
1
xeotek/kadeck:6.3.439a3b37a17c5
curl@7.81.0-1ubuntu1.21
no fix listed
1
xeotek/kadeck:4.2.94c6b04d9ce55
curl@7.68.0-1ubuntu2.16
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
curl@7.88.1-10+deb12u6
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
curl@7.88.1-10+deb12u6
no fix listed
1
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
curl@8.14.1-2+deb13u4
no fix listed
1
yetiplatform/yeti:2.9.09bcbe2650a14
curl@8.14.1-2+deb13u4
no fix listed
1
yetiplatform/yeti:latest9c3006cedcca
curl@8.14.1-2+deb13u4
no fix listed
1
yetiplatform/yeti-frontend:latest709064278c7e
curl@8.14.1-2+deb13u4
no fix listed
1
yetiplatform/yeti-frontend:2.9.0873ef15d267b
curl@8.14.1-2+deb13u4
no fix listed
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
curl@7.68.0-1ubuntu2.7
no fix listed
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
curl@8.5.0-2ubuntu10.6
no fix listed
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
curl@7.81.0-1ubuntu1.3
no fix listed
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
curl@8.5.0-2ubuntu10.6
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
curl@7.68.0-1ubuntu2.7
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
curl@8.5.0-2ubuntu10.6
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
curl@7.81.0-1ubuntu1.3
no fix listed
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
curl@8.5.0-2ubuntu10.6
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
curl@7.68.0-1ubuntu2.7
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
curl@8.5.0-2ubuntu10.6
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
curl@7.81.0-1ubuntu1.3
no fix listed
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
curl@8.5.0-2ubuntu10.6
no fix listed
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
curl@7.88.1-10+deb12u12
no fix listed
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.22.0-r0
1
zimengxiong/excalidash-frontend:0.6.04ec5b20c0303
curl@8.21.0-r0
8.22.0-r0
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
curl@7.81.0-1ubuntu1.25
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.