CVE-2026-80255
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 51st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 828
- of 17,787 indexed, latest versions
- Container images
- 630
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 828 of 17,787 indexed charts deploy, on 630 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+2 more | 8.22.0-r0 | 345 |
| curldeb | 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+12 more | no fix listed | 285 |
Charts affected
828 by stars
Container images carrying it
630 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| glarad/ | 807e453354a7 | curl | 8.22.0-r0 | 1 |
| glpi/ | 4b681082a79e | curl | no fix listed | 1 |
| gluufederation/ | fe944d2e5d0f | curl | 8.22.0-r0 | 1 |
| gomods/ | 0f61d1e62359 | curl | 8.22.0-r0 | 1 |
| gomods/ | 97cc113b34b0 | curl | 8.22.0-r0 | 1 |
| google/ | f7d3e6d6d4f4 | curl | 8.22.0-r0 | 1 |
| gotenberg/ | 206a6c708fc6 | curl | no fix listed | 1 |
| gotenberg/ | 67097317623a | curl | no fix listed | 1 |
| gotenberg/ | a40f92d7419a | curl | no fix listed | 1 |
| grafana/ | 0f86bada30d6 | curl | 8.22.0-r0 | 1 |
| grafana/ | 2d1f9ae67c17 | curl | 8.22.0-r0 | 1 |
| grafana/ | ab5cb380e3ff | curl | 8.22.0-r0 | 1 |
| grafana/ | ba93c9d192e5 | curl | 8.22.0-r0 | 1 |
| graviteeio/ | 4140932887e0 | curl | 8.22.0-r0 | 1 |
| haproxytech/ | 7a3ef2dd8b5b | curl | 8.22.0-r0 | 1 |
| haproxytech/ | b9bffe2d0fd1 | curl | 8.22.0-r0 | 1 |
| haproxytech/ | d90f628d659e | curl | 8.22.0-r0 | 1 |
| hazelcast/ | f086bf0ecb23 | curl | 8.22.0-r0 | 1 |
| healthchecks/ | aa08a61b0dcf | curl | no fix listed | 1 |
| heartexlabs/ | aa461572e8f9 | curl | 8.22.0-r0 | 1 |
| helmforge/ | 61f759a1421f | curl | no fix listed | 1 |
| helmforge/ | fcb7017327d6 | curl | no fix listed | 1 |
| helmforge/ | 7ba0d47b943f | curl | 8.22.0-r0 | 1 |
| helmforge/ | 70e9143d6d92 | curl | 8.22.0-r0 | 1 |
| hiboxsystems/ | b59f01bc0418 | curl | no fix listed | 1 |
| homeassistant/ | 5a531753cea9 | curl | 8.22.0-r0 | 1 |
| hoppscotch/ | d50725df661f | curl | 8.22.0-r0 | 1 |
| huacnlee/ | 560be93229a5 | curl | 8.22.0-r0 | 1 |
| hwdsl2/ | 2e939ffe5913 | curl | 8.22.0-r0 | 1 |
| instill/ | c4a393e601ed | curl | no fix listed | 1 |
| instill/ | ebe12f77a3f9 | curl | no fix listed | 1 |
| instill/ | e980125e5ba5 | curl | no fix listed | 1 |
| inventree/ | a946ec09da3e | curl | no fix listed | 1 |
| itzg/ | 1c59f9631f3b | curl | no fix listed | 1 |
| ixsystems/ | 19c218455cd2 | curl | no fix listed | 1 |
| jellyfin/ | 1694ff069f0c | curl | no fix listed | 1 |
| jellyfin/ | 17285f9cce63 | curl | no fix listed | 1 |
| jellyfin/ | 333b64771663 | curl | no fix listed | 1 |
| jertel/ | 3cbf63f9b7dc | curl | no fix listed | 1 |
| jesec/ | c887dad96b40 | curl | 8.22.0-r0 | 1 |
| jhonbrownn/ | 6936e4f1caeb | curl | 8.22.0-r0 | 1 |
| jitesoft/ | 9996dd28914f | curl | 8.22.0-r0 | 1 |
| jupyterjsc/ | aea53b13f235 | curl | 8.22.0-r0 | 1 |
| kanboard/ | 8df6c4339134 | curl | 8.22.0-r0 | 1 |
| kenchrcum/ | 12fb213debf1 | curl | 8.22.0-r0 | 1 |
| kenchrcum/ | c326e28a8f5f | curl | 8.22.0-r0 | 1 |
| kitware/ | d7767d9b9da4 | curl | no fix listed | 1 |
| kixote/ | 4e9dff179519 | curl | no fix listed | 1 |
| kixote/ | 628f79a08cc7 | curl | no fix listed | 1 |
| kubeshark/ | cc7f07b99fac | curl | 8.22.0-r0 | 1 |