StackRadar

CVE-2026-5773

High

Advisory

Published 29 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,256
of 17,787 indexed, latest versions
Container images
1,180
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,256 of 17,787 indexed charts deploy, on 1,180 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+85 more1:8.14.1-2+deb13u3+e2, 7.47.0-1ubuntu2.19+esm17, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.25+esm5+5 more1,023
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r08.20.0-r0157
OSV records
ALPINE-CVE-2026-5773DEBIAN-CVE-2026-5773UBUNTU-CVE-2026-5773ECHO-73da-59b1-befa
Also known as
USN-8227-1, USN-8525-1

Charts affected

1,256 by stars
ChartLatestAffected imagesRadar Score
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

1,640
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15

Open the chart page →

2,383
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.24

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15

Open the chart page →

13,197
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

1,571

Container images carrying it

1,180 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
2
clamav/clamav:1.4.3_base629a3050df6a
curl@8.17.0-r1
8.20.0-r0
2
dunglas/mercure:v0:v0.24.2916834e49961
curl@8.17.0-r1
8.20.0-r0
2
eqalpha/keydb:latest6537505c4235
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.25+esm5
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.25+esm5
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
2
gisaia/arlas-wui:28.0.3b83b3e067173
curl@8.19.0-r0
8.20.0-r0
2
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
curl@8.19.0-r0
8.20.0-r0
2
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
curl@8.19.0-r0
8.20.0-r0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u15
2
gradiant/ueransim:3.2.6015b30d5fa0f
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.24
2
grafana/grafana:12.3.12175aaa91c96
curl@8.17.0-r1
8.20.0-r0
2
grafana/grafana:12.3.39e1e77ade304
curl@8.17.0-r1
8.20.0-r0
2
grafana/grafana:12.4.1e932bd6ed0e0
curl@8.17.0-r1
8.20.0-r0
2
interlayhq/interbtc:latesta66d0e35e70f
curl@7.68.0-1ubuntu2.25
7.68.0-1ubuntu2.25+esm5
2
istio/kubectl:1.5.10dbb7726d1bf0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm10
2
istio/proxyv2:1.18.0757d28c24100
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.24
2
istio/proxyv2:1.10.3a78b7a165744
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm10
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
jupyterhub/configurable-http-proxy:5.3.0:latest69a7170eeeda
curl@8.19.0-r0
8.20.0-r0
2
kurento/kurento-media-server:latest03c0d34d0828
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
2
library/caddy:2.11.4-alpine:2-alpine5f5c8640aae0
curl@8.19.0-r0
8.20.0-r0
2
library/caddy:latestdf7f1c2fb114
curl@8.19.0-r0
8.20.0-r0
2
library/cassandra:3.11.65aa8400b4b3b
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm10
2
library/cassandra:4.1.37cbcec0086ac
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
2
library/elasticsearch:7.17.35e6ac15bf6a5
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
2
library/elasticsearch:8.19.1289729a95066a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.9
2
library/influxdb:2.7b8d940ca9376
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
2
library/mongo:8.0.20098862b1339f
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.9
2
library/mongo:5.041108d183e97
curl@7.68.0-1ubuntu2.25
7.68.0-1ubuntu2.25+esm5
2
library/mongo:4.2.358b25d51baa1
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10
2
library/nginx:latest6e23479198b9
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
library/nginx:1.27.098f8ec75657d
curl@7.88.1-10+deb12u6
7.88.1-10+deb12u15
2
library/nginx:1.29.49dd288848f44
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
library/phpmyadmin:5.2.16e75aa8f767c
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
2
library/python:3.7eedf63967cdb
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u15
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm17
2
louislam/uptime-kuma:2.5.4917318f9d7be
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
2
louislam/uptime-kuma:2.3.29aeb4e51d038
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.