StackRadar

CVE-2026-5773

High

Advisory

Published 29 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,253
of 17,790 indexed, latest versions
Container images
1,175
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,253 of 17,790 indexed charts deploy, on 1,175 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+85 more1:8.14.1-2+deb13u3+e2, 7.47.0-1ubuntu2.19+esm17, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.25+esm5+5 more1,020
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r08.20.0-r0155
OSV records
ALPINE-CVE-2026-5773DEBIAN-CVE-2026-5773UBUNTU-CVE-2026-5773ECHO-73da-59b1-befa
Also known as
USN-8227-1, USN-8525-1

Charts affected

1,253 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

7,697
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15

Open the chart page →

13,783
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-5773.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

1,571

Container images carrying it

1,175 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.24
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
curl@8.19.0-r0
8.20.0-r0
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
curl@8.17.0-r1
8.20.0-r0
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
curl@7.58.0-2ubuntu3.20
7.58.0-2ubuntu3.24+esm10
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.24
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.24
1
quay.io/groundcover/tools:20260719b705e0cbe171
curl@1:8.14.1-2+deb13u3+e1
1:8.14.1-2+deb13u3+e2
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
curl@7.47.0-1ubuntu2.16
7.47.0-1ubuntu2.19+esm17
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
curl@7.47.0-1ubuntu2.18
7.47.0-1ubuntu2.19+esm17
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u15
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.20.0-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.20.0-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.20.0-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
curl@8.14.1-2
8.14.1-2+deb13u4
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
curl@8.17.0-r1
8.20.0-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.