CVE-2026-80230
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.006
- 46th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,920
- of 17,803 indexed, latest versions
- Container images
- 1,722
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,920 of 17,803 indexed charts deploy, on 1,722 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6+107 more | 1:8.14.1-2+deb13u3+e2 | 1,374 |
| curlapk | 8.10.1-r0, 8.10.1-r1, 8.12.0-r1, 8.12.1-r0+10 more | 8.22.0-r0 | 348 |
- OSV records
- ALPINE-CVE-2026-80230CGA-fch3-mxx2-fc37DEBIAN-CVE-2026-80230UBUNTU-CVE-2026-80230ECHO-1d32-d52b-d070
- Also known as
- CGA-ff7h-5wg5-4v24
Charts affected
1,920 by stars
Container images carrying it
1,722 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| gcr.io/ | 9538fabe49fd | curl | no fix listed | 1 |
| gcr.io/ | ec6f9ea5757b | curl | no fix listed | 1 |
| gcr.io/ | 8d4576f7b98f | curl | no fix listed | 1 |
| gcr.io/ | 9bcfd2abc361 | curl | no fix listed | 1 |
| ghcr.io/ | 7930061993f7 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | c4c1938a973b | curl | no fix listed | 1 |
| ghcr.io/ | 779759172676 | curl | no fix listed | 1 |
| ghcr.io/ | 4c28334f3c79 | curl | no fix listed | 1 |
| ghcr.io/ | cc9a028d9c43 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 459010a02aff | curl | no fix listed | 1 |
| ghcr.io/ | d110504d551d | curl | no fix listed | 1 |
| ghcr.io/ | 18689773150d | curl | no fix listed | 1 |
| ghcr.io/ | 71be54e99608 | curl | no fix listed | 1 |
| ghcr.io/ | d332ae2410f8 | curl | no fix listed | 1 |
| ghcr.io/ | 13e267ad7d94 | curl | no fix listed | 1 |
| ghcr.io/ | 2d4d776f6362 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | e9c2ce635b89 | curl | no fix listed | 1 |
| ghcr.io/ | f527d10769ac | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | f9104080d9a7 | curl | no fix listed | 1 |
| ghcr.io/ | 4a2824296412 | curl | no fix listed | 1 |
| ghcr.io/ | 20518335f9f9 | curl | no fix listed | 1 |
| ghcr.io/ | 67ffb0309acb | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 70d9d1b78d39 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | fcbab3a24880 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 5889bea38e56 | curl | no fix listed | 1 |
| ghcr.io/ | 10b7945d4f09 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 8766ba08bf1a | curl | no fix listed | 1 |
| ghcr.io/ | 8eb6e492fe3c | curl | no fix listed | 1 |
| ghcr.io/ | 1aba0ffe55ea | curl | no fix listed | 1 |
| ghcr.io/ | ab63d26a8a2c | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 72f35584026d | curl | no fix listed | 1 |
| ghcr.io/ | 16759fa523f8 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | b6373349a301 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 6fde1edc0983 | curl | no fix listed | 1 |
| ghcr.io/ | d600eac6283f | curl | no fix listed | 1 |
| ghcr.io/ | 2ed0183564d7 | curl | no fix listed | 1 |
| ghcr.io/ | 853e6f105b51 | curl | no fix listed | 1 |
| ghcr.io/ | ca7dc7362968 | curl | no fix listed | 1 |
| ghcr.io/ | 443d9850a688 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 129212faf248 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 0e99f12bb040 | curl | no fix listed | 1 |
| ghcr.io/ | d9d796a1b846 | curl | no fix listed | 1 |
| ghcr.io/ | a058034ca006 | curl | no fix listed | 1 |
| ghcr.io/ | 896e4926e0d7 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 8d943799621b | curl | no fix listed | 1 |
| ghcr.io/ | 726a947bb65b | curl | no fix listed | 1 |
| ghcr.io/ | 246dc2160efe | curl | no fix listed | 1 |
| ghcr.io/ | 8136c3beda7a | curl | no fix listed | 1 |
| ghcr.io/ | 40b804fce7f9 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | fce5b6fd161c | curl | 8.22.0-r0 | 1 |