StackRadar

CVE-2026-3805

High

Advisory

Published 11 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
228
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 228 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
curlapk8.17.0-r1, 8.18.0-r08.19.0-r0105
curldeb1:8.14.1-2+deb13u3+e1, 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3+2 more1:8.14.1-2+deb13u3+e2, 8.14.1-2+deb13u4, 8.14.1-2ubuntu1.2101
OSV records
ALPINE-CVE-2026-3805DEBIAN-CVE-2026-3805UBUNTU-CVE-2026-3805ECHO-4deb-219d-e7eb
Also known as
USN-8084-1

Charts affected

228 by stars
ChartLatestAffected imagesRadar Score
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,802
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

3,001
persistence-elasticsecurecodebox-persistence-elastic5.7.01 of 1See more

persistence-elastic securecodebox-persistence-elastic 5.7.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
securecodebox/persistence-elastic-dashboard-importer:5.7.0afcefbd56d61
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

885
ccx-monitoringseveralnines0.6.211 of 7See more

ccx-monitoring severalnines 0.6.21

1 of the 7 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

7,708
bffshortlink0.2.11 of 1See more

bff shortlink 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,690
linkshortlink0.7.31 of 1See more

link shortlink 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,674
link-uishortlink0.7.51 of 1See more

link-ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,321
uishortlink0.7.51 of 1See more

ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,321
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
curl@8.14.1-2
8.14.1-2+deb13u4

Open the chart page →

3,962
ingress-nginxsoftonic4.15.11 of 2See more

ingress-nginx softonic 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,547
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
grafana/grafana:12.3.2ba93c9d192e5
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

4,974
squadsquadVerified publisher0.1.111 of 1See more

squad squad 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
cm2network/squad:latest8cba47f53df5
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

2,487
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,702
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,157
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

3,389
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,129
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4

Open the chart page →

4,674
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,396
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

3,240
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,115
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,043
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

4,212
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,825
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,675
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

2,620
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4

Open the chart page →

2,018
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

5,459
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-3805.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.19.0-r0

Open the chart page →

1,571

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
7
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
curl@8.17.0-r1
8.19.0-r0
6
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
curl@8.17.0-r1
8.19.0-r0
5
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
curl@8.17.0-r1
8.19.0-r0
3
alpine/k8s:1.32.12048f8d9c8cc7
curl@8.18.0-r0
8.19.0-r0
2
alpine/kubectl:1.35.49ccd82364762
curl@8.17.0-r1
8.19.0-r0
2
alpine/kubectl:1.35.2ec8f734b0a10
curl@8.17.0-r1
8.19.0-r0
2
clamav/clamav:1.4.3_base629a3050df6a
curl@8.17.0-r1
8.19.0-r0
2
dunglas/mercure:v0:v0.24.2916834e49961
curl@8.17.0-r1
8.19.0-r0
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
grafana/grafana:12.3.12175aaa91c96
curl@8.17.0-r1
8.19.0-r0
2
grafana/grafana:12.3.39e1e77ade304
curl@8.17.0-r1
8.19.0-r0
2
grafana/grafana:12.4.1e932bd6ed0e0
curl@8.17.0-r1
8.19.0-r0
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
library/nginx:latest6e23479198b9
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
library/nginx:1.29.49dd288848f44
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
requarks/wiki:2:latest68f0d1848261
curl@8.17.0-r1
8.19.0-r0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
curl@8.17.0-r1
8.19.0-r0
2
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
curl@8.17.0-r1
8.19.0-r0
2
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
alpine/helm:4.1.0905a068da431
curl@8.18.0-r0
8.19.0-r0
1
alpine/kubectl:1.36.01ee9df6316d4
curl@8.17.0-r1
8.19.0-r0
1
alpine/kubectl:1.35.0862d86046bbc
curl@8.17.0-r1
8.19.0-r0
1
alpine/kubectl:1.35.3c4a11ae9a1cb
curl@8.17.0-r1
8.19.0-r0
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
appwrite/appwrite:1.9.01aaa70127114
curl@8.17.0-r1
8.19.0-r0
1
appwrite/console:8.7.383dcdc8492ac6
curl@8.17.0-r1
8.19.0-r0
1
aquasec/trivy:0.69.3bcc376de8d77
curl@8.17.0-r1
8.19.0-r0
1
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
curl@8.17.0-r1
8.19.0-r0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
curl@8.14.1-2
8.14.1-2+deb13u4
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
curl@8.17.0-r1
8.19.0-r0
1
blackducksoftware/blackduck-alert-rabbitmq:8.4.08f422b18d171
curl@8.17.0-r1
8.19.0-r0
1
boky/postfix:5.1.0aafc77238423
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
cars10/elasticvue:1.15.0efddf4fa0fd8
curl@8.17.0-r1
8.19.0-r0
1
castopod/castopod:1.15.54e4f0440520f
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
chocobozzz/peertube:v8.1.5052712130691
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
cm2network/squad:latest8cba47f53df5
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
conductoross/conductor:3.31.09fba127693e6
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
dependencytrack/frontend:4.14.200560b57a6cf
curl@8.17.0-r1
8.19.0-r0
1
docuseal/docuseal:2.4.17493fd7f6728
curl@8.17.0-r1
8.19.0-r0
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
curl@8.14.1-2
8.14.1-2+deb13u4
1
dunglas/mercure:v0.24.080fcb704a741
curl@8.17.0-r1
8.19.0-r0
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
elautoestopista/aeneabot:4.2.1125ba620d528
curl@8.17.0-r1
8.19.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.