StackRadar

CVE-2026-80231

High

Advisory

Published 6 Sept 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
406
of 17,787 indexed, latest versions
Container images
342
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 406 of 17,787 indexed charts deploy, on 342 images.

Affected packageAffected versionsFixed inImages
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+3 more8.22.0-r0342
OSV records
ALPINE-CVE-2026-80231
Trending
Rank 26 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

406 by stars
ChartLatestAffected imagesRadar Score
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,639
wordpress-alpinewordpress-alpine1.5.182 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

2 of the 6 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
ghcr.io/shesselink81/nginx-alpine:7.1.0.09783481cad2a
curl@8.21.0-r0
8.22.0-r0
ghcr.io/shesselink81/wordpress-alpine:7.1.0.032ace450bcd9
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

3,990
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

878
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

7,849

Container images carrying it

342 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/axoflow/axosyslog:4.27.00379598e9ad2
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/bitwarden/web:2026.8.00767b242240d
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/bysamio/casepack-docs:0.8.0443d9850a688
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/bysamio/casepack-spa:0.30.0129212faf248
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/cloudquery/cloudquery:6.40.040b804fce7f9
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/cobbler/cobbler-web:v1.1.0c17978fb13dd
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/dakera-ai/dakera-dashboard:0.3.292e059589f7f7
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/dictionarry-hub/profilarr:2.2.0ddcdd0f34004
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/ethpandaops/dispatchoor-web:latest18e30413dac2
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/ethpandaops/syncoor-web:master60d7c38d6062
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/fluxcd/kustomize-controller:v1.9.23aecec8bafdb
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/gchq/cyberchef:11.0.045082a0ac41d
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/gluufederation/flex/persistence-loader:0.0.0-nightlyc26589258dec
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/home-operations/bazarr:1.6.0cd63bbd0986c
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/home-operations/lidarr:3.1.29df1e14c8e09
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/home-operations/prowlarr:2.4.0b7da6e9defbe
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/home-operations/qbittorrent:5.2.224f2d793cb7f
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/home-operations/qbittorrent:5.2.34fcf15b7f265
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/home-operations/radarr:6.4.3:6.4.3.106450ebb4ae26ee9
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/home-operations/radarr:6.2.1a566e7d364b9
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/home-operations/sonarr:4.0.171989718e9fce
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/home-operations/tautulli:2.17.12183820d45a1
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/hotio/qbittorrent:release-5.2.007198d49e5b4
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/kozea/radicale:3.7.600a3d8e1f04b
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/linuxserver/freshrss:1.29.17f7f276244da
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/linuxserver/radarr:6.0.4c8a55bd83672
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/linuxserver/syslog-ng:4.10.247fae7f540f9
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/manyfold3d/manyfold-solo:0.147.2ed5a792b0e8d
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/marcuwynu23/vite-app-sample:latest21247f2b97c4
curl@8.17.0-r1
8.22.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.