StackRadar

CVE-2026-80231

High

Advisory

Published 6 Sept 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
405
of 17,787 indexed, latest versions
Container images
341
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 405 of 17,787 indexed charts deploy, on 341 images.

Affected packageAffected versionsFixed inImages
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+3 more8.22.0-r0341
OSV records
ALPINE-CVE-2026-80231
Trending
Rank 26 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

405 by stars
ChartLatestAffected imagesRadar Score
wordpress-alpinewordpress-alpine1.5.182 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

2 of the 6 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
ghcr.io/shesselink81/nginx-alpine:7.1.0.09783481cad2a
curl@8.21.0-r0
8.22.0-r0
ghcr.io/shesselink81/wordpress-alpine:7.1.0.032ace450bcd9
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

3,990
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

878
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-80231.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
curl@8.21.0-r0
8.22.0-r0

Open the chart page →

7,849

Container images carrying it

341 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/mkutlak/alluredeck-ui:0.41.0c19509b1b336
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/mydecisive/octant-ui:0.0.1-testing61e4066b22fb
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/observal/observal-web:1.13.1738acf65cba7
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-03:0.0.0-2026-08-1714527ca5d2a9
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/open-telemetry/demo:3.0.0-telemetry-docs3519858704e7
curl@8.19.0-r0
8.22.0-r0
1
ghcr.io/open-telemetry/demo:3.0.0-quote6bc8f7f6809e
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/processone/ejabberd:latest5aeb0faa39cf
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/prophetse7en/clonarr:latest9400d298b37a
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/sergelogvinov/ipsec:5.236f4e651d1fe
curl@8.20.0-r1
8.22.0-r0
1
ghcr.io/shesselink81/nginx-alpine:7.1.0.09783481cad2a
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/shesselink81/wordpress-alpine:7.1.0.032ace450bcd9
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/silverbulletmd/silverbullet:2.10.027b5724cc367
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/stefanprodan/podinfo:6.15.0ec73780a8425
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/teq-cloud/iteq-web:0.3.3-beta0acbe2f2e1ea
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/thoroslives/zilean:v3.10.1bce6aca0f6ca
curl@8.12.1-r0
8.22.0-r0
1
ghcr.io/timothepoznanski/poznote:6.80.0045035db3a20
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
curl@8.21.0-r0
8.22.0-r0
1
ghcr.io/zalando/postgres-operator:v2.0.275f69eac43ac
curl@8.21.0-r0
8.22.0-r0
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
curl@8.19.0-r0
8.22.0-r0
1
quay.io/codefresh/dind:3.0.250885ab519dac
curl@8.21.0-r0
8.22.0-r0
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
curl@8.17.0-r1
8.22.0-r0
1
quay.io/shesselink81/anna-nginx:v1.31.1120c19fa8a918
curl@8.21.0-r0
8.22.0-r0
1
quay.io/shesselink81/hesselinkme-nginx:v1.31.114f43beb13fc2
curl@8.21.0-r0
8.22.0-r0
1
registry.gitlab.com/gitlab-ci-utils/curl-jq:latestb564745b6cb0
curl@8.21.0-r0
8.22.0-r0
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
curl@8.20.0-r0
8.22.0-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
curl@8.17.0-r1
8.22.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.