StackRadar

CVE-2026-80229

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
850
of 17,787 indexed, latest versions
Container images
656
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 850 of 17,787 indexed charts deploy, on 656 images.

Affected packageAffected versionsFixed inImages
curlapk8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.15.0-r4+11 more8.22.0-r0371
curldeb8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+12 moreno fix listed285
OSV records
ALPINE-CVE-2026-80229DEBIAN-CVE-2026-80229UBUNTU-CVE-2026-80229CGA-7v23-69r9-9qwj
Also known as
CGA-8mx8-358x-g636

Charts affected

850 by stars
ChartLatestAffected imagesRadar Score
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

3,442
metabasehelmforgeVerified publisher1.2.281 of 3See more

metabase helmforge 1.2.28

1 of the 3 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.16c6dd0c6a7861
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

1,805
netboxhelmforgeVerified publisher2.0.11 of 4See more

netbox helmforge 2.0.1

1 of the 4 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
curl@8.18.0-1ubuntu2.3
no fix listed

Open the chart page →

4,321
nextcloudhelmforgeVerified publisher1.0.01 of 3See more

nextcloud helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4-apachede4ad9389386
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

7,041
opencloudhelmforgeVerified publisher1.0.01 of 1See more

opencloud helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
opencloudeu/opencloud:7.2.46d992ccc5f1c
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

663
openreel-videohelmforgeVerified publisher1.0.31 of 1See more

openreel-video helmforge 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
helmforge/openreel-video:v0.5.07ba0d47b943f
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,086
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
curl@8.14.1-2
no fix listed

Open the chart page →

4,741
pimcorehelmforgeVerified publisher2.0.11 of 6See more

pimcore helmforge 2.0.1

1 of the 6 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
dunglas/mercure:v0.24.2916834e49961
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

3,200
poznotehelmforgeVerified publisher2.0.21 of 1See more

poznote helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
ghcr.io/timothepoznanski/poznote:6.80.0045035db3a20
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

483
strapihelmforgeVerified publisher2.3.141 of 3See more

strapi helmforge 2.3.14

1 of the 3 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
helmforge/strapi-base:5.52.270e9143d6d92
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

2,073
strava-statisticshelmforgeVerified publisher1.1.161 of 2See more

strava-statistics helmforge 1.1.16

1 of the 2 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
robiningelbrecht/strava-statistics:v5.0.040842cdfd616
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

846
jellyfinhelm-l3st86Verified publisher0.1.81 of 1See more

jellyfin helm-l3st86 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
jellyfin/jellyfin:latestaefb67e6a7ff
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

2,615
openaevhelm-openbasVerified publisher2.0.51 of 7See more

openaev helm-openbas 2.0.5

1 of the 7 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
rustfs/rustfs:1.0.0-beta.1241fe89380f41
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

7,502
release-cleanerhelm-release-cleanerVerified publisher1.0.01 of 1See more

release-cleaner helm-release-cleaner 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
alpine/helm:4.1.0905a068da431
curl@8.18.0-r0
8.22.0-r0

Open the chart page →

2,001
my-nginxhelmtaiwo0.1.01 of 1See more

my-nginx helmtaiwo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
webserverhongshaoyangVerified publisher0.1.31 of 1See more

webserver hongshaoyang 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/httpd:alpine1b766f17b840
curl@8.20.0-r1
8.22.0-r0

Open the chart page →

902
paperlesshpVerified publisher0.1.12 of 5See more

paperless hp 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.3467097317623a
curl@8.20.0-5~bpo13+1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

26,579
nginx-charthyomin-nginx0.1.01 of 1See more

nginx-chart hyomin-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
nginx-charthyun-nginx0.1.01 of 1See more

nginx-chart hyun-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

57,728
multicaicoretechVerified publisher0.4.421 of 5See more

multica icoretech 0.4.42

1 of the 5 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

2,730
nextjsicoretechVerified publisher1.2.01 of 1See more

nextjs icoretech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
web-chartimcherry57780.1.01 of 1See more

web-chart imcherry5778 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
onechartimioVerified publisher0.76.01 of 1See more

onechart imio 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,954
op-stackinfradao0.0.11 of 1See more

op-stack infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

3,157
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4b760f0d2547
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

781
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

398
inventreeinventreeOfficialVerified publisher0.4.282 of 2See more

inventree inventree 0.4.28

2 of the 2 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
curl@8.14.1-2+deb13u4
no fix listed
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

5,757
iteqiteqOfficialVerified publisher0.3.31 of 3See more

iteq iteq 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
ghcr.io/teq-cloud/iteq-web:0.3.3-beta0acbe2f2e1ea
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

777
dynamic-ip-loadbalancer-controlleritsmethemojoVerified publisher0.1.01 of 1See more

dynamic-ip-loadbalancer-controller itsmethemojo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,692
tekton-git-listeneritsmethemojoVerified publisher0.1.11 of 1See more

tekton-git-listener itsmethemojo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/buildpack-deps:scmac978b783657
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,178
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/postgres:alpined3e1620b530c
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

45,392
web-chartjaeeyun-ktcloudlab0.1.01 of 1See more

web-chart jaeeyun-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
nginx-chartjaeki-nginx0.1.01 of 1See more

nginx-chart jaeki-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
jasper-uijasperVerified publisher1.0.341 of 1See more

jasper-ui jasper 1.0.34

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,571
manyfoldjeffrescVerified publisher1.0.31 of 1See more

manyfold jeffresc 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,961
jellyfinjellyfin--jellyfin-helm3.0.01 of 1See more

jellyfin jellyfin--jellyfin-helm 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.717285f9cce63
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

2,967
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,487
nginx-chartjinbok-nginx0.1.01 of 1See more

nginx-chart jinbok-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
nginx-chartjiungVerified publisher0.1.01 of 1See more

nginx-chart jiung 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
nginx-chartjongh09160.1.01 of 1See more

nginx-chart jongh0916 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
moreillon/group-manager-front:latest5f0a38498271
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

59,560
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,967
jupyter-hub-customizationsjupyter-jscVerified publisher0.27.171 of 4See more

jupyter-hub-customizations jupyter-jsc 0.27.17

1 of the 4 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:1.291881968aff6f
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

3,402
jupyter-nginxjupyter-jscVerified publisher0.1.31 of 1See more

jupyter-nginx jupyter-jsc 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

3,520
jwks-mergejwks-merge0.1.01 of 2See more

jwks-merge jwks-merge 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,045
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

10,560
clonarrk8s-chartsVerified publisher0.10.11 of 1See more

clonarr k8s-charts 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-80229.

Container imageDigestPackageFixed in
ghcr.io/prophetse7en/clonarr:latest9400d298b37a
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

439

Container images carrying it

656 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kanboard/kanboard:v1.2.548df6c4339134
curl@8.21.0-r0
8.22.0-r0
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
curl@8.17.0-r1
8.22.0-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
curl@8.17.0-r1
8.22.0-r0
1
kitware/cdash:v5.3.0d7767d9b9da4
curl@8.14.1-2+deb13u4
no fix listed
1
kixote/typemill4e9dff179519
curl@8.14.1-2+deb13u4
no fix listed
1
kixote/typemill628f79a08cc7
curl@8.14.1-2+deb13u4
no fix listed
1
kubeshark/front:v53.4cc7f07b99fac
curl@8.21.0-r0
8.22.0-r0
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
curl@8.17.0-r1
8.22.0-r0
1
langgenius/dify-sandbox:0.2.15750e1111426e
curl@8.19.0-3
no fix listed
1
lbenicio/stremio-web:latest732f9003de33
curl@8.17.0-r1
8.22.0-r0
1
library/adminer:51596436ca855
curl@8.21.0-r0
8.22.0-r0
1
library/adminer:5.4.2-standalone983261ecc40a
curl@8.21.0-r0
8.22.0-r0
1
library/buildpack-deps:scmac978b783657
curl@8.14.1-2+deb13u4
no fix listed
1
library/caddy:latest13ba145cba2f
curl@8.19.0-r0
8.22.0-r0
1
library/caddy:2.11.2-alpine834468128c76
curl@8.17.0-r1
8.22.0-r0
1
library/docker:29.7.2-dind3ef33f2e220b
curl@8.21.0-r0
8.22.0-r0
1
library/eclipse-temurin:211f79c73404fb
curl@8.18.0-1ubuntu2.5
no fix listed
1
library/eclipse-temurin:2185f00967bcc6
curl@8.18.0-1ubuntu2.4
no fix listed
1
library/golang:latest512690a56605
curl@8.14.1-2+deb13u4
no fix listed
1
library/matomo:5.13.0-apache8e6bdd396496
curl@8.14.1-2+deb13u4
no fix listed
1
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
curl@8.21.0-r0
8.22.0-r0
1
library/nextcloud:31.0.10-apacheb7faa1653c39
curl@8.14.1-2+deb13u2
no fix listed
1
library/nextcloud:34.0.4-apachede4ad9389386
curl@8.14.1-2+deb13u4
no fix listed
1
library/nginx:1.291881968aff6f
curl@8.14.1-2+deb13u2
no fix listed
1
library/nginx:1.31.0-alpine2f07d83bf561
curl@8.19.0-r0
8.22.0-r0
1
library/nginx:1.31.3-alpine4a73073bd557
curl@8.21.0-r0
8.22.0-r0
1
library/nginx:1.29.8-alpine5616878291a2
curl@8.17.0-r1
8.22.0-r0
1
library/nginx:1.28-alpinea8b39bd9cf0f
curl@8.17.0-r1
8.22.0-r0
1
library/node:latestf5d1cc40abc1
curl@8.14.1-2+deb13u4
no fix listed
1
library/php:8-fpm-alpine22a4c414bb8e
curl@8.21.0-r0
8.22.0-r0
1
library/php:8.4-fpm59fa733c9af6
curl@8.14.1-2+deb13u4
no fix listed
1
library/postgres:18.3-alpine54451ecb8ab3
curl@8.17.0-r1
8.22.0-r0
1
library/postgres:18.4-alpine3.249a8afca54e78
curl@8.21.0-r0
8.22.0-r0
1
library/python:3.1070c9cc675605
curl@8.14.1-2+deb13u4
no fix listed
1
library/python:3.9da5aee29682d
curl@8.14.1-2
no fix listed
1
library/redmine:6.1.204ac44a2595b
curl@8.14.1-2+deb13u3
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
curl@8.14.1-2+deb13u3
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
curl@8.14.1-2+deb13u2
no fix listed
1
librenms/librenms:26.8.28194a4a9ff49
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/bazarr:latesta20fb11a440d
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/bookstack:26.05.202605282ebf97852661
curl@8.19.0-r0
8.22.0-r0
1
linuxserver/deluge:2.2.09505c64720af
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/heimdall:2.8.3287e48152967
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/lidarr:3.1.0c74c32408fdf
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/mariadb:latestcb61ec331e80
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/plex:1.43.41f6f97d76e7b
curl@8.18.0-1ubuntu2.5
no fix listed
1
linuxserver/prowlarr:version-2.4.0.53974fd7a166c8f4
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/prowlarr:2.5.291844fa2c927
curl@8.21.0-r0
8.22.0-r0
1
linuxserver/prowlarr:2.4.0.5397-ls149a46d0ce0a823
curl@8.19.0-r0
8.22.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.