CVE-2026-19931
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.012
- 66th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,808
- of 17,797 indexed, latest versions
- Container images
- 1,620
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,808 of 17,797 indexed charts deploy, on 1,620 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 more | no fix listed | 1,269 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 351 |
- OSV records
- ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931CGA-4wpj-77jq-67v6ECHO-5bd0-12f6-d009
- Also known as
- CGA-h86j-p398-8x8h
- Trending
- Rank 35 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,808 by stars
Container images carrying it
1,620 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 27b5724cc367 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 61b2eb9eed8e | curl | no fix listed | 1 |
| ghcr.io/ | 3c8375dc5487 | curl | no fix listed | 1 |
| ghcr.io/ | 5ecb16015aa8 | curl | no fix listed | 1 |
| ghcr.io/ | 1dcca70c6446 | curl | no fix listed | 1 |
| ghcr.io/ | 2bc7b260e44e | curl | no fix listed | 1 |
| ghcr.io/ | ec73780a8425 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 3b3670fce70b | curl | no fix listed | 1 |
| ghcr.io/ | 91fca773a63f | curl | no fix listed | 1 |
| ghcr.io/ | 89969b78fb07 | curl | no fix listed | 1 |
| ghcr.io/ | bf816072380e | curl | no fix listed | 1 |
| ghcr.io/ | d7bdfa7b41da | curl | no fix listed | 1 |
| ghcr.io/ | 8e3cb38953a3 | curl | no fix listed | 1 |
| ghcr.io/ | 26953ec68d5d | curl | no fix listed | 1 |
| ghcr.io/ | d7c43c3135c6 | curl | no fix listed | 1 |
| ghcr.io/ | 0bc598b2ac9a | curl | no fix listed | 1 |
| ghcr.io/ | 220c5e4e1a3d | curl | no fix listed | 1 |
| ghcr.io/ | e1351a977607 | curl | no fix listed | 1 |
| ghcr.io/ | 99fd4cb0f4fe | curl | no fix listed | 1 |
| ghcr.io/ | c73527cde81c | curl | no fix listed | 1 |
| ghcr.io/ | ee9cf22a39ab | curl | no fix listed | 1 |
| ghcr.io/ | d2c3218c7f9f | curl | no fix listed | 1 |
| ghcr.io/ | 6daa2dc7556b | curl | no fix listed | 1 |
| ghcr.io/ | 0acbe2f2e1ea | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 38eba84b2be8 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | bce6aca0f6ca | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 182664fe1ca0 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | d1cff2560c67 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 9d01bf9c9224 | curl | no fix listed | 1 |
| ghcr.io/ | 28f263fe06f7 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 73ca19b41745 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | e3f80c0625aa | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | fa32d116cf20 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | a56dfe91f5b1 | curl | no fix listed | 1 |
| ghcr.io/ | 916746209ac5 | curl | no fix listed | 1 |
| ghcr.io/ | 63873f3f698e | curl | no fix listed | 1 |
| ghcr.io/ | a3c27ee3fb2f | curl | no fix listed | 1 |
| ghcr.io/ | 86ab9effd1a5 | curl | no fix listed | 1 |
| ghcr.io/ | 6e04659a3baa | curl | no fix listed | 1 |
| ghcr.io/ | 8622ea9e43c0 | curl | no fix listed | 1 |
| ghcr.io/ | 1572e12bc93c | curl | no fix listed | 1 |
| ghcr.io/ | dbaa8527bf4c | curl | no fix listed | 1 |
| ghcr.io/ | 282f840612d9 | curl | no fix listed | 1 |
| ghcr.io/ | d19d886d5090 | curl | no fix listed | 1 |
| ghcr.io/ | e0f2f8c97598 | curl | no fix listed | 1 |
| ghcr.io/ | 5a6fe78d4d15 | curl | no fix listed | 1 |
| ghcr.io/ | 54082566391e | curl | no fix listed | 1 |
| ghcr.io/ | 7bff29dcec72 | curl | no fix listed | 1 |
| ghcr.io/ | 75f69eac43ac | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | ce435c77651e | curl | no fix listed | 1 |