StackRadar

CVE-2026-80231

High

Advisory

Published 6 Sept 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
409
of 17,781 indexed, latest versions
Container images
345
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 409 of 17,781 indexed charts deploy, on 345 images.

Affected packageAffected versionsFixed inImages
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+3 more8.22.0-r0345
OSV records
ALPINE-CVE-2026-80231
Trending
Rank 26 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

409 by stars
ChartLatestAffected imagesRadar Score
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

904
victoria-metrics-k8s-stackwenerme0.92.11 of 7See more

victoria-metrics-k8s-stack wenerme 0.92.1

1 of the 7 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
grafana/grafana:13.1.17cb8c64c4d57
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

1,889
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

5,459
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,639
wordpress-alpinewordpress-alpine1.5.182 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

2 of the 6 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
ghcr.io/shesselink81/nginx-alpine:7.1.0.09783481cad2a
curl@8.21.0-r0
8.22.0-r0
ghcr.io/shesselink81/wordpress-alpine:7.1.0.032ace450bcd9
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

3,990
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

878
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

7,849

Container images carrying it

345 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
espocrm/espocrm:10.0.8-fpm-alpine4bd92daf5f0c
curl@8.20.0-r0
8.22.0-r0
1
etherpad/etherpad:latest6020e7b57f4b
curl@8.21.0-r0
8.22.0-r0
1
etherpad/etherpad:2.7.2b723fe5f2594
curl@8.17.0-r1
8.22.0-r0
1
filebrowser/filebrowser:v2.63.15-s6dbac07403040
curl@8.19.0-r0
8.22.0-r0
1
folioci/mod-graphql:latestf0655a6a08fd
curl@8.20.0-r0
8.22.0-r0
1
fosrl/pangolin:1.13.0c32ad797ab96
curl@8.17.0-r1
8.22.0-r0
1
garethgeorge/backrest:v1.14.1b85297975428
curl@8.21.0-r0
8.22.0-r0
1
geonode/geoserver_data:2.28.4-latest435cbc5f3f05
curl@8.20.0-r1
8.22.0-r0
1
gitea/act_runner:nightly7940221bcfc9
curl@8.17.0-r1
8.22.0-r0
1
gitea/act_runner:0.3.1c2a169c5e998
curl@8.17.0-r1
8.22.0-r0
1
gitea/gitea:1.27.3-rootless1c17ecaead42
curl@8.21.0-r0
8.22.0-r0
1
gitea/gitea:1.27.134e3f6b75f5c
curl@8.21.0-r0
8.22.0-r0
1
gitea/gitea:1.26.27d13848af126
curl@8.19.0-r0
8.22.0-r0
1
gitea/gitea:1.27.387a67ee09d3a
curl@8.21.0-r0
8.22.0-r0
1
glarad/mcp-management-portal-clr:0.6.8807e453354a7
curl@8.21.0-r0
8.22.0-r0
1
gluufederation/cloudtools:4.5.17-1fe944d2e5d0f
curl@8.21.0-r0
8.22.0-r0
1
gomods/athens:v0.17.10f61d1e62359
curl@8.17.0-r1
8.22.0-r0
1
gomods/athens:v0.18.197cc113b34b0
curl@8.20.0-r0
8.22.0-r0
1
google/cloud-sdk:alpinef7d3e6d6d4f4
curl@8.20.0-r0
8.22.0-r0
1
grafana/grafana:13.0.10f86bada30d6
curl@8.17.0-r1
8.22.0-r0
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
curl@8.17.0-r1
8.22.0-r0
1
grafana/grafana:13.1.3ab5cb380e3ff
curl@8.21.0-r0
8.22.0-r0
1
grafana/grafana:12.3.2ba93c9d192e5
curl@8.17.0-r1
8.22.0-r0
1
graviteeio/ae-engine:3.0.24140932887e0
curl@8.20.0-r0
8.22.0-r0
1
haproxytech/haproxy-alpine:3.4.37a3ef2dd8b5b
curl@8.20.0-r0
8.22.0-r0
1
haproxytech/haproxy-unified-gateway:1.0.7b9bffe2d0fd1
curl@8.20.0-r0
8.22.0-r0
1
haproxytech/kubernetes-ingress:3.2.14d90f628d659e
curl@8.20.0-r0
8.22.0-r0
1
hazelcast/hazelcast:latestf086bf0ecb23
curl@8.17.0-r1
8.22.0-r0
1
heartexlabs/label-studio:latestaa461572e8f9
curl@8.17.0-r1
8.22.0-r0
1
helmforge/openreel-video:v0.5.07ba0d47b943f
curl@8.17.0-r1
8.22.0-r0
1
helmforge/strapi-base:5.52.270e9143d6d92
curl@8.21.0-r0
8.22.0-r0
1
homeassistant/home-assistant:2026.75a531753cea9
curl@8.20.0-r1
8.22.0-r0
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
curl@8.21.0-r0
8.22.0-r0
1
huacnlee/gobackup:v3.1.1560be93229a5
curl@8.21.0-r0
8.22.0-r0
1
hwdsl2/ipsec-vpn-server:latest2e939ffe5913
curl@8.20.0-r0
8.22.0-r0
1
jesec/flood:4.14.3c887dad96b40
curl@8.20.0-r1
8.22.0-r0
1
jhonbrownn/elchi:v1.5.146936e4f1caeb
curl@8.21.0-r0
8.22.0-r0
1
jitesoft/kubectl:latest9996dd28914f
curl@8.21.0-r0
8.22.0-r0
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
curl@8.20.0-r0
8.22.0-r0
1
kanboard/kanboard:v1.2.548df6c4339134
curl@8.21.0-r0
8.22.0-r0
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
curl@8.17.0-r1
8.22.0-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
curl@8.17.0-r1
8.22.0-r0
1
kubeshark/front:v53.4cc7f07b99fac
curl@8.21.0-r0
8.22.0-r0
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
curl@8.17.0-r1
8.22.0-r0
1
lbenicio/stremio-web:latest732f9003de33
curl@8.17.0-r1
8.22.0-r0
1
library/adminer:51596436ca855
curl@8.21.0-r0
8.22.0-r0
1
library/adminer:5.4.2-standalone983261ecc40a
curl@8.21.0-r0
8.22.0-r0
1
library/caddy:latest13ba145cba2f
curl@8.19.0-r0
8.22.0-r0
1
library/caddy:2.11.2-alpine834468128c76
curl@8.17.0-r1
8.22.0-r0
1
library/docker:29.7.2-dind3ef33f2e220b
curl@8.21.0-r0
8.22.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.