CVE-2026-3805
HighAdvisory
Published 11 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 53rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 228
- of 17,781 indexed, latest versions
- Container images
- 206
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 228 of 17,781 indexed charts deploy, on 206 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 8.17.0-r1, 8.18.0-r0 | 8.19.0-r0 | 105 |
| curldeb | 1:8.14.1-2+deb13u3+e1, 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3+2 more | 1:8.14.1-2+deb13u3+e2, 8.14.1-2+deb13u4, 8.14.1-2ubuntu1.2 | 101 |
- OSV records
- ALPINE-CVE-2026-3805DEBIAN-CVE-2026-3805UBUNTU-CVE-2026-3805ECHO-4deb-219d-e7eb
- Also known as
- USN-8084-1
Charts affected
228 by stars
Container images carrying it
206 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | e59ebde55709 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 000c5ee5ee96 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | d090bb2060d9 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 18e30413dac2 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 45082a0ac41d | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 05002092c621 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 46a71d75dfd3 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 067e54e2e107 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 9df1e14c8e09 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | dab0e07502a3 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | bb82ad6668f8 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 2183820d45a1 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | cd25a5cc3f1b | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | b434cb9287ee | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | f8d06a32b1b2 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 45f648c382a0 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 9a69aa14dc3e | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 708446bc6783 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 757bdd779345 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | c8a55bd83672 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 20fde516ce31 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | d14ca4d82475 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 21247f2b97c4 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 517556c8b144 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | fae3c1f04311 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 8be69156acbb | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 61e4066b22fb | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 034151b61a80 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 3e56bdd1b90d | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 7f91594d5eb3 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 4b05bcd28e69 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 57ad9565bff3 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 665f2f5cc548 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | b89f83345532 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | fce820a03964 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 45bdeaf3fcd6 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | c92d1e223f5c | curl | 1:8.14.1-2+deb13u3+e2 | 1 |
| ghcr.io/ | 17666811f6a7 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | cdf1e3329bfe | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 1485ff93cbf9 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 39953b387b61 | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 61b2eb9eed8e | curl | 8.14.1-2+deb13u4 | 1 |
| ghcr.io/ | 38eba84b2be8 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 28f263fe06f7 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | 73ca19b41745 | curl | 8.19.0-r0 | 1 |
| ghcr.io/ | e3f80c0625aa | curl | 8.19.0-r0 | 1 |
| public.ecr.aws/ | af8cea3b8538 | curl | 1:8.14.1-2+deb13u3+e2 | 1 |
| quay.io/ | d2d3400664e8 | curl | 8.19.0-r0 | 1 |
| quay.io/ | b705e0cbe171 | curl | 1:8.14.1-2+deb13u3+e2 | 1 |
| quay.io/ | d8f66f4117fe | curl | 8.14.1-2+deb13u4 | 1 |