StackRadar

CVE-2026-5773

High

Advisory

Published 29 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,256
of 17,787 indexed, latest versions
Container images
1,180
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,256 of 17,787 indexed charts deploy, on 1,180 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+85 more1:8.14.1-2+deb13u3+e2, 7.47.0-1ubuntu2.19+esm17, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.25+esm5+5 more1,023
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r08.20.0-r0157
OSV records
ALPINE-CVE-2026-5773DEBIAN-CVE-2026-5773UBUNTU-CVE-2026-5773ECHO-73da-59b1-befa
Also known as
USN-8227-1, USN-8525-1

Charts affected

1,256 by stars
ChartLatestAffected imagesRadar Score
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

1,640
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15

Open the chart page →

2,383
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.24

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15

Open the chart page →

13,197
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

1,571

Container images carrying it

1,180 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
linuxserver/lazylibrarian:version-1152df82f93d2560e233
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm10
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.24+esm10
1
linuxserver/plex:1.25.24a13ced2326c
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
1
linuxserver/prowlarr:2.4.0.5397-ls149a46d0ce0a823
curl@8.19.0-r0
8.20.0-r0
1
linuxserver/qbittorrent:5.2.2dd24a5f3db32
curl@8.19.0-r0
8.20.0-r0
1
linuxserver/sonarr:version-4.0.17.295202bc962946fe
curl@8.19.0-r0
8.20.0-r0
1
linuxserver/unifi-controller:8.0.240ae315a3a456
curl@7.68.0-1ubuntu2.21
7.68.0-1ubuntu2.25+esm5
1
linuxserver/unifi-controller:7.3.83ab105cc50322
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.25+esm5
1
lis314/project-zomboid-docker:latestaa2089c37920
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
litmuschaos/mongo:4.2.899961210d467
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.24+esm10
1
livekit/ingress:v1.2.21ab01641b366
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.24
1
localstack/localstack:3.19d278167f2b7
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
loeken/sonarr:4.0.17b940520a2236
curl@8.19.0-r0
8.20.0-r0
1
longhornio/longhorn-manager:v1.2.3dca34321452c
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm10
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
louislam/uptime-kuma:2.5.33e24e96c89ef
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
louislam/uptime-kuma:2.0.24c364ef96aad
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
louislam/uptime-kuma:2.4.091e963bfda56
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
1
luligu/matterbridge:3.0.28f97884bebc2
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
1
m11s/decap-cms:0.2.11-s30cd6810c9885
curl@8.19.0-r0
8.20.0-r0
1
makersquad/harp-proxy:0.8.1a40dd258c527
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
curl@7.68.0-1ubuntu2.25
7.68.0-1ubuntu2.25+esm5
1
martinhelmich/typo3:12.4c83a4f3fd7ae
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
mathesar/mathesar:0.12.0091757cb01fe
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15
1
matterlabs/external-node:v24.0.06cbfea4c694a
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
mautic/mautic:7-apacheeb8cc73d97e1
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
mawad98/backstage-pyactions:demo99422c56a274
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
mbround18/valheim:3.1.070bd4da591cd
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.24
1
mediagis/nominatim:3.7c15e941485ef
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm5
1
mediagis/nominatim:4.2d0eae7b51374
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
1
middlewareeng/middleware:0.3.1747d880812f1
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
milvusdb/milvus:v2.2.13a3a55e1c1497
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.25+esm5
1
mindsdb/mindsdb:latest163011c09299
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
curl@7.68.0-1ubuntu2.23
7.68.0-1ubuntu2.25+esm5
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
mlikiowa/napcat-docker:latest1336a777f9a4
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.24
1
moby/buildkit:v0.31.0a095b3d11ce1
curl@8.19.0-r0
8.20.0-r0
1
moreillon/api-proxy:latestd7d4a5463525
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
moreillon/camera-viewer:lateste418cc694bd5
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
moreillon/food-manager:lateste8fd856e593d
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
moreillon/group-manager:latest3caa8f710ee0
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
moreillon/group-manager-front:latest5f0a38498271
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
moreillon/user-manager-front:v5.1.06597e6b98d21
curl@7.88.1-10+deb12u6
7.88.1-10+deb12u15
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.