StackRadar

CVE-2026-19931

Critical

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,801
of 17,803 indexed, latest versions
Container images
1,611
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,801 of 17,803 indexed charts deploy, on 1,611 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 moreno fix listed1,263
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more8.22.0-r0348
OSV records
ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931CGA-4wpj-77jq-67v6ECHO-5bd0-12f6-d009
Also known as
CGA-h86j-p398-8x8h
Trending
Rank 35 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,801 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.42 of 6See more

zoo-project-dru zoo-project 0.10.4

2 of the 6 container images this version deploys carry CVE-2026-19931.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
curl@8.21.0-r0
8.22.0-r0
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
curl@7.81.0-1ubuntu1.25
no fix listed

Open the chart page →

7,936

Container images carrying it

1,611 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
curl@8.14.1-2+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
curl@7.88.1-10+deb12u4
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
curl@8.14.1-2+deb13u2
no fix listed
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
curl@1:8.14.1-2+deb13u3+e1
no fix listed
1
ghcr.io/processone/ejabberd:latest5aeb0faa39cf
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/prophetse7en/clonarr:latest9400d298b37a
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
curl@8.14.1-2+deb13u3
no fix listed
1
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
curl@8.14.1-2+deb13u3
no fix listed
1
ghcr.io/quenchworks/images/documentdbbe72db1f2865
curl@8.21.0-r2
8.22.0-r0
1
ghcr.io/quenchworks/images/drupal1969d8357d81
curl@8.21.0-r2
8.22.0-r0
1
ghcr.io/quenchworks/images/ingress-nginx0dd302223669
curl@8.21.0-r2
8.22.0-r0
1
ghcr.io/quenchworks/images/mongodbe540b335ce42
curl@8.21.0-r2
8.22.0-r0
1
ghcr.io/quenchworks/images/nextclouda113d014a824
curl@8.21.0-r2
8.22.0-r0
1
ghcr.io/quenchworks/images/postgres-documentdbffcc1485b970
curl@8.21.0-r2
8.22.0-r0
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
curl@8.18.0-1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
curl@8.5.0-2ubuntu10.8
no fix listed
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
curl@8.5.0-2ubuntu10.8
no fix listed
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
curl@8.5.0-2ubuntu10.8
no fix listed
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
curl@8.5.0-2ubuntu10.8
no fix listed
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
curl@8.5.0-2ubuntu10.8
no fix listed
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
curl@8.5.0-2ubuntu10.6
no fix listed
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
curl@7.88.1-10+deb12u12
no fix listed
1
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
curl@8.14.1-2+deb13u2
no fix listed
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/sergelogvinov/ipsec:5.236f4e651d1fe
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
curl@7.88.1-10+deb12u12
no fix listed
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
curl@8.5.0-2ubuntu10.6
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/shesselink81/nginx-alpine:7.1.0.09783481cad2a
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/shesselink81/wordpress-alpine:7.1.0.032ace450bcd9
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/silverbulletmd/silverbullet:2.10.027b5724cc367
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
curl@8.14.1-2+deb13u2
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
curl@7.68.0-1ubuntu2.14
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
curl@7.68.0-1ubuntu2.14
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
curl@7.68.0-1ubuntu2.14
no fix listed
1
ghcr.io/steadybit/agent:2.4.52bc7b260e44e
curl@8.14.1-2+deb13u4
no fix listed
1
ghcr.io/stefanprodan/podinfo:6.15.0ec73780a8425
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
curl@8.5.0-2ubuntu10.8
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.