CVE-2026-19931
CriticalAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.012
- 65th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,819
- of 17,787 indexed, latest versions
- Container images
- 1,637
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,819 of 17,787 indexed charts deploy, on 1,637 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.68.0-1ubuntu2.2, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.5+78 more | no fix listed | 1,272 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 365 |
- OSV records
- ALPINE-CVE-2026-19931DEBIAN-CVE-2026-19931UBUNTU-CVE-2026-19931CGA-4wpj-77jq-67v6ECHO-5bd0-12f6-d009
- Also known as
- CGA-h86j-p398-8x8h
- Trending
- Rank 21 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,819 by stars
Container images carrying it
1,637 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| metabase/ | 9491ed11c901 | curl | 8.22.0-r0 | 2 |
| moby/ | 504731e577c2 | curl | 8.22.0-r0 | 2 |
| moreillon/ | c9f85db3baa5 | curl | no fix listed | 2 |
| moreillon/ | e1c9bfab5c16 | curl | no fix listed | 2 |
| moreillon/ | b067dbbbb6af | curl | no fix listed | 2 |
| n8nio/ | 14c4285bc303 | curl | 8.22.0-r0 | 2 |
| n8nio/ | 5d9f0cc5672b | curl | 8.22.0-r0 | 2 |
| nacos/ | 1c191c30c8cd | curl | no fix listed | 2 |
| nginxinc/ | cb92301e719d | curl | no fix listed | 2 |
| obsidiandynamics/ | 5337c9e0e2de | curl | no fix listed | 2 |
| opencloudeu/ | 1691ad6612a3 | curl | no fix listed | 2 |
| opencloudeu/ | 27cb9b952f0d | curl | no fix listed | 2 |
| opencloudeu/ | 5b176baa3694 | curl | no fix listed | 2 |
| opencloudeu/ | 6e8b2df6c5a4 | curl | no fix listed | 2 |
| opencloudeu/ | 82f888a34440 | curl | no fix listed | 2 |
| opencloudeu/ | e0ac35a9576e | curl | no fix listed | 2 |
| opendatacube/ | 668cbb41473c | curl | no fix listed | 2 |
| openebs/ | 99f5116f5cb8 | curl | 8.22.0-r0 | 2 |
| pgautoupgrade/ | 48b448825656 | curl | 8.22.0-r0 | 2 |
| piomin/ | 871f784dd6bc | curl | no fix listed | 2 |
| polyaxon/ | eca6952b20e6 | curl | no fix listed | 2 |
| polyaxon/ | 024ff3fa775e | curl | no fix listed | 2 |
| qichenxu4pd/ | f3a8502bc21b | curl | no fix listed | 2 |
| quickwit/ | 363ff56ce456 | curl | no fix listed | 2 |
| rajnandan1/ | 30407afca731 | curl | no fix listed | 2 |
| requarks/ | 68f0d1848261 | curl | 8.22.0-r0 | 2 |
| streamnative/ | 0e6d7aa3ef32 | curl | no fix listed | 2 |
| svtechnmaa/ | b2987abe57d3 | curl | no fix listed | 2 |
| swaggerapi/ | 3d9316996884 | curl | 8.22.0-r0 | 2 |
| syncthing/ | 775c4aac4862 | curl | 8.22.0-r0 | 2 |
| tzahi12345/ | 2f943d584711 | curl | no fix listed | 2 |
| uffizzi/ | 0344805f267b | curl | no fix listed | 2 |
| vdiogov/ | 6945f84f0058 | curl | no fix listed | 2 |
| wolveix/ | e103700ae6ae | curl | no fix listed | 2 |
| zabbix/ | 349b924472a7 | curl | no fix listed | 2 |
| ghcr.io/ | 536358d7b17e | curl | no fix listed | 2 |
| ghcr.io/ | b1ba7b054af2 | curl | no fix listed | 2 |
| ghcr.io/ | 82d0b161161d | curl | no fix listed | 2 |
| ghcr.io/ | a7805a8a60ff | curl | 8.22.0-r0 | 2 |
| ghcr.io/ | 5be52524664c | curl | no fix listed | 2 |
| ghcr.io/ | 5f545698e907 | curl | no fix listed | 2 |
| ghcr.io/ | 7962759d99d7 | curl | no fix listed | 2 |
| ghcr.io/ | c80ae007ce2c | curl | no fix listed | 2 |
| ghcr.io/ | 103fbcec2314 | curl | no fix listed | 2 |
| ghcr.io/ | cd264d33efd4 | curl | no fix listed | 2 |
| ghcr.io/ | 612d76760b54 | curl | 8.22.0-r0 | 2 |
| ghcr.io/ | a1bc133af84e | curl | 8.22.0-r0 | 2 |
| ghcr.io/ | 4f89afef9010 | curl | 8.22.0-r0 | 2 |
| ghcr.io/ | 02fd613b6a35 | curl | no fix listed | 2 |
| ghcr.io/ | 3db8145349a3 | curl | no fix listed | 2 |