StackRadar

CVE-2026-3805

High

Advisory

Published 11 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
228
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 228 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
curlapk8.17.0-r1, 8.18.0-r08.19.0-r0105
curldeb1:8.14.1-2+deb13u3+e1, 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3+2 more1:8.14.1-2+deb13u3+e2, 8.14.1-2+deb13u4, 8.14.1-2ubuntu1.2101
OSV records
ALPINE-CVE-2026-3805DEBIAN-CVE-2026-3805UBUNTU-CVE-2026-3805ECHO-4deb-219d-e7eb
Also known as
USN-8084-1

Charts affected

228 by stars
ChartLatestAffected imagesRadar Score
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,802
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

3,001
persistence-elasticsecurecodebox-persistence-elastic5.7.01 of 1See more

persistence-elastic securecodebox-persistence-elastic 5.7.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
securecodebox/persistence-elastic-dashboard-importer:5.7.0afcefbd56d61
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

885
ccx-monitoringseveralnines0.6.211 of 7See more

ccx-monitoring severalnines 0.6.21

1 of the 7 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

7,708
bffshortlink0.2.11 of 1See more

bff shortlink 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,690
linkshortlink0.7.31 of 1See more

link shortlink 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,674
link-uishortlink0.7.51 of 1See more

link-ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,321
uishortlink0.7.51 of 1See more

ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,321
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
curl@8.14.1-2
8.14.1-2+deb13u4

Open the chart page →

3,962
ingress-nginxsoftonic4.15.11 of 2See more

ingress-nginx softonic 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,547
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
grafana/grafana:12.3.2ba93c9d192e5
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

4,974
squadsquadVerified publisher0.1.111 of 1See more

squad squad 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
cm2network/squad:latest8cba47f53df5
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

2,487
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,702
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,157
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

3,389
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,129
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4

Open the chart page →

4,674
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,396
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

3,240
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,115
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,043
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

4,212
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,825
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,675
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,620
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4

Open the chart page →

2,018
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

5,459
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,571

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
emqx/emqx:5.8.935b46f7aa7a0
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.19.0-r0
1
escaping/core-keeper-dedicated:latest87fa79255962
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
esphome/esphome:2026.7.44866347cb5b4
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
esphome/esphome:2026.8.285abea33854b
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
espocrm/espocrm:9.3.101b5a24504ed9
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
etherpad/etherpad:2.7.2b723fe5f2594
curl@8.17.0-r1
8.19.0-r0
1
ethpandaops/assertoor:latest1efa2fba6711
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
curl@8.14.1-2
8.14.1-2+deb13u4
1
fireflyiii/core:version-6.6.6ae69fdd95cde
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
fluent/fluent-bit:4.2.6a52221a2a3eb
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
fosrl/pangolin:1.13.0c32ad797ab96
curl@8.17.0-r1
8.19.0-r0
1
gitea/act_runner:nightly7940221bcfc9
curl@8.17.0-r1
8.19.0-r0
1
gitea/act_runner:0.3.1c2a169c5e998
curl@8.17.0-r1
8.19.0-r0
1
gomods/athens:v0.17.10f61d1e62359
curl@8.17.0-r1
8.19.0-r0
1
grafana/grafana:13.0.10f86bada30d6
curl@8.17.0-r1
8.19.0-r0
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
curl@8.17.0-r1
8.19.0-r0
1
grafana/grafana:12.3.2ba93c9d192e5
curl@8.17.0-r1
8.19.0-r0
1
hazelcast/hazelcast:latestf086bf0ecb23
curl@8.17.0-r1
8.19.0-r0
1
heartexlabs/label-studio:latestaa461572e8f9
curl@8.17.0-r1
8.19.0-r0
1
helmforge/fastmcp-server:0.2.061f759a1421f
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
helmforge/openreel-video:v0.5.07ba0d47b943f
curl@8.17.0-r1
8.19.0-r0
1
hiboxsystems/marge-bot:0.16.0b59f01bc0418
curl@8.14.1-2
8.14.1-2+deb13u4
1
instill/artifact-backend:b28766ac4a393e601ed
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
instill/model-backend:611f0f2e980125e5ba5
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
8.14.1-2+deb13u4
1
jellyfin/jellyfin:10.11.81694ff069f0c
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
jellyfin/jellyfin:10.11.717285f9cce63
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
jellyfin/jellyfin:10.11.6333b64771663
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
curl@8.17.0-r1
8.19.0-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
curl@8.17.0-r1
8.19.0-r0
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
curl@8.17.0-r1
8.19.0-r0
1
lbenicio/stremio-web:latest732f9003de33
curl@8.17.0-r1
8.19.0-r0
1
library/caddy:2.11.2-alpine834468128c76
curl@8.17.0-r1
8.19.0-r0
1
library/nextcloud:31.0.10-apacheb7faa1653c39
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
library/nginx:1.291881968aff6f
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
library/nginx:1.29.8-alpine5616878291a2
curl@8.17.0-r1
8.19.0-r0
1
library/nginx:1.28-alpinea8b39bd9cf0f
curl@8.17.0-r1
8.19.0-r0
1
library/postgres:18.3-alpine54451ecb8ab3
curl@8.17.0-r1
8.19.0-r0
1
library/python:3.9da5aee29682d
curl@8.14.1-2
8.14.1-2+deb13u4
1
library/redmine:6.1.204ac44a2595b
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
library/wordpress:php8.1-apachef73396626d2f
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
mawad98/backstage-pyactions:demo99422c56a274
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
mindsdb/mindsdb:latest163011c09299
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
moreillon/group-manager-front:latest5f0a38498271
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
curl@8.17.0-r1
8.19.0-r0
1
mybb/mybb:1.8f2a54bce31c5
curl@8.17.0-r1
8.19.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.