StackRadar

CVE-2026-6276

High

Advisory

Published 29 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
920
of 17,787 indexed, latest versions
Container images
901
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 920 of 17,787 indexed charts deploy, on 901 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4+37 more1:8.14.1-2+deb13u3+e2, 7.81.0-1ubuntu1.24, 8.5.0-2ubuntu10.9, 8.14.1-2+deb13u4+1 more747
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r08.20.0-r0154
OSV records
ALPINE-CVE-2026-6276DEBIAN-CVE-2026-6276UBUNTU-CVE-2026-6276ECHO-78b1-43ab-d59f
Also known as
USN-8227-1

Charts affected

920 by stars
ChartLatestAffected imagesRadar Score
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9

Open the chart page →

7,628
api-gatewaywallarmVerified publisher0.2.01 of 1See more

api-gateway wallarm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
wallarm/api-gateway:0.2.0a3d4d2f780e8
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

2,288
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4

Open the chart page →

2,018
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

5,984
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.24

Open the chart page →

6,232
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
no fix listed

Open the chart page →

10,001
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

8,811
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

9,117
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

5,459
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24

Open the chart page →

9,248
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.9

Open the chart page →

2,191
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

7,624
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

5,542
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

1,639
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

2,473
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.24

Open the chart page →

14,100
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

7,673
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

13,677
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-6276.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

1,571

Container images carrying it

901 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
istio/proxyv2:1.18.0757d28c24100
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.24
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
curl@7.88.1-10+deb12u4
no fix listed
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
jupyterhub/configurable-http-proxy:5.3.0:latest69a7170eeeda
curl@8.19.0-r0
8.20.0-r0
2
kurento/kurento-media-server:latest03c0d34d0828
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
2
library/caddy:2.11.4-alpine:2-alpine5f5c8640aae0
curl@8.19.0-r0
8.20.0-r0
2
library/caddy:latestdf7f1c2fb114
curl@8.19.0-r0
8.20.0-r0
2
library/cassandra:4.1.37cbcec0086ac
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
2
library/elasticsearch:8.19.1289729a95066a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.9
2
library/influxdb:2.7b8d940ca9376
curl@7.88.1-10+deb12u14
no fix listed
2
library/mongo:8.0.20098862b1339f
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.9
2
library/nginx:latest6e23479198b9
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
library/nginx:1.27.098f8ec75657d
curl@7.88.1-10+deb12u6
no fix listed
2
library/nginx:1.29.49dd288848f44
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
library/phpmyadmin:5.2.16e75aa8f767c
curl@7.88.1-10+deb12u8
no fix listed
2
library/python:3.7eedf63967cdb
curl@7.88.1-10+deb12u1
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
2
louislam/uptime-kuma:2.5.4917318f9d7be
curl@7.88.1-10+deb12u14
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
curl@7.88.1-10+deb12u14
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
curl@7.88.1-10+deb12u14
no fix listed
2
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.20.0-r0
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
curl@7.88.1-10+deb12u6
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
curl@7.88.1-10+deb12u4
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
curl@7.88.1-10+deb12u4
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
curl@7.88.1-10+deb12u8
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
curl@7.88.1-10+deb12u8
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
curl@7.88.1-10+deb12u8
no fix listed
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
curl@7.88.1-10+deb12u8
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
curl@7.88.1-10+deb12u8
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
curl@7.88.1-10+deb12u8
no fix listed
2
opendatacube/ows:latest668cbb41473c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.24
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
curl@7.88.1-10+deb12u5
no fix listed
2
quickwit/quickwit:v0.8.2363ff56ce456
curl@7.88.1-10+deb12u5
no fix listed
2
rajnandan1/kener:3.2.1930407afca731
curl@7.88.1-10+deb12u12
no fix listed
2
requarks/wiki:2:latest68f0d1848261
curl@8.17.0-r1
8.20.0-r0
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
curl@7.81.0-1ubuntu1.2
7.81.0-1ubuntu1.24
2
syncthing/syncthing:2.1.1775c4aac4862
curl@8.19.0-r0
8.20.0-r0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.24
2
uffizzi/controller:latest0344805f267b
curl@7.88.1-10+deb12u5
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
curl@7.88.1-10+deb12u6
no fix listed
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.24
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
curl@7.81.0-1ubuntu1.21
7.81.0-1ubuntu1.24
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
2
ghcr.io/cinnyapp/cinny:v4.12.6a7805a8a60ff
curl@8.19.0-r0
8.20.0-r0
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.24
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.24
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
curl@7.88.1-10+deb12u14
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
curl@7.88.1-10+deb12u15
no fix listed
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.