StackRadar

CVE-2026-7168

Medium

Advisory

Published 29 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,201
of 17,787 indexed, latest versions
Container images
1,133
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,201 of 17,787 indexed charts deploy, on 1,133 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.58.0-2ubuntu3.3, 7.58.0-2ubuntu3.5, 7.58.0-2ubuntu3.6+71 more1:8.14.1-2+deb13u3+e2, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.25+esm5, 7.81.0-1ubuntu1.24+4 more979
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r08.20.0-r0154
OSV records
ALPINE-CVE-2026-7168DEBIAN-CVE-2026-7168UBUNTU-CVE-2026-7168ECHO-992e-5e26-c10d
Also known as
USN-8227-1, USN-8525-1

Charts affected

1,201 by stars
ChartLatestAffected imagesRadar Score
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

9,847
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
curl@8.14.1-2
8.14.1-2+deb13u4

Open the chart page →

7,489
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9

Open the chart page →

7,300
arlas-aiasarlas-stackVerified publisher28.8.010 of 22See more

arlas-aias arlas-stack 28.8.0

10 of the 22 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
gisaia/arlas-wui:28.0.3b83b3e067173
curl@8.19.0-r0
8.20.0-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
curl@8.19.0-r0
8.20.0-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
curl@8.19.0-r0
8.20.0-r0
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15

Open the chart page →

40,238
arlas-uisarlas-stackVerified publisher28.8.03 of 4See more

arlas-uis arlas-stack 28.8.0

3 of the 4 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
gisaia/arlas-wui:28.0.3b83b3e067173
curl@8.19.0-r0
8.20.0-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
curl@8.19.0-r0
8.20.0-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

2,985
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.25+esm5

Open the chart page →

23,353
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.25+esm5
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.25+esm5

Open the chart page →

22,568
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm5

Open the chart page →

9,369
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.24

Open the chart page →

10,061
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24

Open the chart page →

18,277
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
curl@7.68.0-1ubuntu2.19
7.68.0-1ubuntu2.25+esm5

Open the chart page →

7,936
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm10

Open the chart page →

5,363
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u15
library/mongo:4.4.66efa05203990
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm10

Open the chart page →

45,363
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.25+esm5

Open the chart page →

13,913
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.24
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15

Open the chart page →

32,501
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

9,412
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.24

Open the chart page →

6,908
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15

Open the chart page →

6,297
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
kuzwolka/aws9:news3e8880fbbb96
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
kuzwolka/aws9:blog4a7707410bf1
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
kuzwolka/aws9:shop84a9d9766345
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15

Open the chart page →

18,344
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.24

Open the chart page →

3,268
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
infiniflow/infinity:v0.7.0992c87a68612
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.24

Open the chart page →

5,823
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4

Open the chart page →

2,738
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15

Open the chart page →

6,297
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm5
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm5
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm5

Open the chart page →

20,671
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10

Open the chart page →

20,190
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.24

Open the chart page →

7,190
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9

Open the chart page →

5,059
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm10

Open the chart page →

22,891
tenzu-frontbiru-scop3.1.01 of 1See more

tenzu-front biru-scop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

845
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15

Open the chart page →

10,145
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.2.6a52221a2a3eb
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4

Open the chart page →

9,521
blackduck-alertblackduck8.4.02 of 4See more

blackduck-alert blackduck 8.4.0

2 of the 4 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
curl@8.17.0-r1
8.20.0-r0
blackducksoftware/blackduck-alert-rabbitmq:8.4.08f422b18d171
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

4,292
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5

Open the chart page →

13,459
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.25+esm5

Open the chart page →

15,253
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
sysnet4admin/colosseum-prm:log5802bfcd7fed
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15

Open the chart page →

26,996
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
library/cassandra:3.11.65aa8400b4b3b
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm10

Open the chart page →

19,229
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

8,323
Filebrowserbrandan-schmitz-helm-chartsVerified publisher1.3.11 of 1See more

Filebrowser brandan-schmitz-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.63.15-s6dbac07403040
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

995
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15

Open the chart page →

27,274
qbittorrentbrandan-schmitz-helm-chartsVerified publisher2.2.01 of 1See more

qbittorrent brandan-schmitz-helm-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
linuxserver/qbittorrent:5.2.2dd24a5f3db32
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

956
sonarrbrandan-schmitz-helm-chartsVerified publisher2.0.101 of 1See more

sonarr brandan-schmitz-helm-charts 2.0.10

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
linuxserver/sonarr:version-4.0.17.295202bc962946fe
curl@8.19.0-r0
8.20.0-r0

Open the chart page →

866
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.02 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10

Open the chart page →

20,190
pagesbrixton-pages1.0.02 of 3See more

pages brixton-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10

Open the chart page →

20,190
ombibryanalves0.4.01 of 1See more

ombi bryanalves 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.24+esm10

Open the chart page →

10,776
plexbryanalves0.5.01 of 1See more

plex bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5

Open the chart page →

6,707
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9

Open the chart page →

14,352
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5

Open the chart page →

11,869
caddycaddyVerified publisher0.0.41 of 1See more

caddy caddy 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
library/caddy:2.11.2-alpine834468128c76
curl@8.17.0-r1
8.20.0-r0

Open the chart page →

1,677
pagescamden-pages1.0.02 of 3See more

pages camden-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-7168.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10

Open the chart page →

20,190

Container images carrying it

1,133 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
istio/proxyv2:1.14.1df69c1a7af7c
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.25+esm5
1
istio/ztunnel:1.25.005f3972d80a9
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
1
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
8.14.1-2+deb13u4
1
jacobalberty/unifi:v7.1.664a3616625dda
curl@7.58.0-2ubuntu3.18
7.58.0-2ubuntu3.24+esm10
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
curl@7.58.0-2ubuntu3.24
7.58.0-2ubuntu3.24+esm10
1
jaedb/iris:latest048cfbf58d57
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
jakowenko/double-take:1.6.0b858bac9e32a
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
1
jedi132000/nextapp:latestdc2a81e92f23
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.25+esm5
1
jellyfin/jellyfin:10.11.81694ff069f0c
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
jellyfin/jellyfin:10.11.717285f9cce63
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
jellyfin/jellyfin:10.11.6333b64771663
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
curl@7.88.1-10+deb12u6
7.88.1-10+deb12u15
1
jellyfin/jellyfin:10.10.77ae36aab93ef
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
jellyfin/jellyfin:10.10.696b09723b22f
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
jhipster/jhipster-registry:latest7184525acd4d
curl@7.68.0-1ubuntu2.25
7.68.0-1ubuntu2.25+esm5
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
curl@7.68.0-1ubuntu2.21
7.68.0-1ubuntu2.25+esm5
1
jordan/icinga2:latestf75025fe8ea8
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
josh5/unmanic:0.2.64d49c4816260
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm5
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm5
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
curl@8.5.0-2ubuntu10.4
8.5.0-2ubuntu10.9
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.24
1
kayrosuno/kping:latestf3bd44b29b0d
curl@8.5.0-2ubuntu10.7
8.5.0-2ubuntu10.9
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
curl@8.17.0-r1
8.20.0-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
curl@8.17.0-r1
8.20.0-r0
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.25+esm5
1
kinseii/wazuh-agent:4.14.17160eb143728
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
knspar/phronetis-operator:0.1.60c4f0543ee58
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
kong/httpbin:latesta6ac46531193
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.24
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.24
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.25+esm5
1
krontechnology/aapm-service:1.1.39dd602db8baa
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.24
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm10
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.9
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
curl@8.17.0-r1
8.20.0-r0
1
kusionstack/kusion:v0.14.0126c8f0b0976
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.24
1
kuzwolka/aws9:main1ad759b961b1
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
kuzwolka/aws9:news3e8880fbbb96
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
kuzwolka/aws9:blog4a7707410bf1
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
kuzwolka/aws9:shop84a9d9766345
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.24
1
laly9999/node-app:1dd0e503913e1
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
langflowai/langflow-frontend:latest54f67f1961fe
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.