CVE-2026-6276
HighAdvisory
Published 29 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.003
- 22nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 926
- of 17,787 indexed, latest versions
- Container images
- 912
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 926 of 17,787 indexed charts deploy, on 912 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4+37 more | 1:8.14.1-2+deb13u3+e2, 7.81.0-1ubuntu1.24, 8.5.0-2ubuntu10.9, 8.14.1-2+deb13u4+1 more | 755 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0 | 8.20.0-r0 | 157 |
- OSV records
- ALPINE-CVE-2026-6276DEBIAN-CVE-2026-6276UBUNTU-CVE-2026-6276ECHO-78b1-43ab-d59f
- Also known as
- USN-8227-1
Charts affected
926 by stars
Container images carrying it
912 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| istio/ | ce27c9ce43c8 | curl | 8.5.0-2ubuntu10.9 | 1 |
| istio/ | 70f9d1fe5fff | curl | 7.81.0-1ubuntu1.24 | 1 |
| istio/ | 325156535773 | curl | 8.5.0-2ubuntu10.9 | 1 |
| istio/ | 9c3d6a218181 | curl | 8.5.0-2ubuntu10.9 | 1 |
| istio/ | ac0284d75ec9 | curl | 7.81.0-1ubuntu1.24 | 1 |
| istio/ | ce9d87606701 | curl | 7.81.0-1ubuntu1.24 | 1 |
| istio/ | db08d6963975 | curl | 7.81.0-1ubuntu1.24 | 1 |
| istio/ | f8b0e412ac4a | curl | 8.5.0-2ubuntu10.9 | 1 |
| istio/ | 05f3972d80a9 | curl | 8.5.0-2ubuntu10.9 | 1 |
| ixsystems/ | 19c218455cd2 | curl | 8.14.1-2+deb13u4 | 1 |
| jaedb/ | 048cfbf58d57 | curl | no fix listed | 1 |
| jbtronics/ | 5db71f6db59d | curl | no fix listed | 1 |
| jellyfin/ | 1694ff069f0c | curl | 8.14.1-2+deb13u4 | 1 |
| jellyfin/ | 17285f9cce63 | curl | 8.14.1-2+deb13u4 | 1 |
| jellyfin/ | 17c3a8d9dddb | curl | no fix listed | 1 |
| jellyfin/ | 333b64771663 | curl | 8.14.1-2+deb13u4 | 1 |
| jellyfin/ | 79fb3d73a3e9 | curl | no fix listed | 1 |
| jellyfin/ | 7ae36aab93ef | curl | no fix listed | 1 |
| jellyfin/ | 96b09723b22f | curl | no fix listed | 1 |
| jenkins/ | 95313257a8cd | curl | no fix listed | 1 |
| jenkins/ | de4fea113221 | curl | no fix listed | 1 |
| jhoncytech/ | 18c3ca1f411e | curl | no fix listed | 1 |
| jordan/ | f75025fe8ea8 | curl | no fix listed | 1 |
| josh5/ | 4d49c4816260 | curl | 7.81.0-1ubuntu1.24 | 1 |
| juicedata/ | 95008ba63318 | curl | no fix listed | 1 |
| kafkace/ | 7adc206bf5a4 | curl | 8.5.0-2ubuntu10.9 | 1 |
| kafkakraft/ | 062d697db7e5 | curl | 7.81.0-1ubuntu1.24 | 1 |
| kafkakraft/ | f261ad288fce | curl | 7.81.0-1ubuntu1.24 | 1 |
| kafkakraft/ | 2e4b593b878b | curl | 7.81.0-1ubuntu1.24 | 1 |
| kayrosuno/ | f3bd44b29b0d | curl | 8.5.0-2ubuntu10.9 | 1 |
| kenchrcum/ | 12fb213debf1 | curl | 8.20.0-r0 | 1 |
| kenchrcum/ | c326e28a8f5f | curl | 8.20.0-r0 | 1 |
| kimai/ | 3084f1e5ecdc | curl | no fix listed | 1 |
| kinseii/ | 7160eb143728 | curl | no fix listed | 1 |
| knspar/ | 0c4f0543ee58 | curl | no fix listed | 1 |
| kong/ | a6ac46531193 | curl | 7.81.0-1ubuntu1.24 | 1 |
| krontechnology/ | 1cc7d5be6529 | curl | 7.81.0-1ubuntu1.24 | 1 |
| krontechnology/ | 9dd602db8baa | curl | 7.81.0-1ubuntu1.24 | 1 |
| kubeovn/ | 6722b54eb5c0 | curl | 8.5.0-2ubuntu10.9 | 1 |
| kubeshop/ | d8e1af6aca99 | curl | no fix listed | 1 |
| kubevirtmanager/ | 1b98f1b5977a | curl | 8.20.0-r0 | 1 |
| kusionstack/ | 126c8f0b0976 | curl | 7.81.0-1ubuntu1.24 | 1 |
| kuzwolka/ | 1ad759b961b1 | curl | no fix listed | 1 |
| kuzwolka/ | 3e8880fbbb96 | curl | no fix listed | 1 |
| kuzwolka/ | 4a7707410bf1 | curl | no fix listed | 1 |
| kuzwolka/ | 84a9d9766345 | curl | no fix listed | 1 |
| kvalitetsit/ | f0af0ba589af | curl | 7.81.0-1ubuntu1.24 | 1 |
| laly9999/ | dd0e503913e1 | curl | no fix listed | 1 |
| langflowai/ | 54f67f1961fe | curl | no fix listed | 1 |
| langgenius/ | bf8027ddccf3 | curl | no fix listed | 1 |