CVE-2026-80255
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 51st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 828
- of 17,787 indexed, latest versions
- Container images
- 630
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 828 of 17,787 indexed charts deploy, on 630 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+2 more | 8.22.0-r0 | 345 |
| curldeb | 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+12 more | no fix listed | 285 |
Charts affected
828 by stars
Container images carrying it
630 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 05b8cb60c354 | curl | no fix listed | 106 |
| library/ | d5792f71a949 | curl | no fix listed | 23 |
| library/ | d3e1620b530c | curl | 8.22.0-r0 | 17 |
| jenkins/ | c1e4c349365f | curl | no fix listed | 13 |
| grafana/ | f772d434e8fa | curl | 8.22.0-r0 | 12 |
| jellyfin/ | aefb67e6a7ff | curl | no fix listed | 7 |
| library/ | 3a8a8d6b5289 | curl | no fix listed | 7 |
| vaultwarden/ | 094b5689ed81 | curl | no fix listed | 7 |
| ghcr.io/ | aa810a36942c | curl | no fix listed | 7 |
| library/ | 5a93c470ae82 | curl | no fix listed | 6 |
| nginxinc/ | 0c79d56aee56 | curl | 8.22.0-r0 | 6 |
| dpage/ | 2f4ce946ddf8 | curl | 8.22.0-r0 | 5 |
| library/ | f742dcf1b6ca | curl | 8.22.0-r0 | 5 |
| library/ | 979c38c2228d | curl | no fix listed | 5 |
| registry.k8s.io/ | 594ceea76b01 | curl | 8.22.0-r0 | 5 |
| decisionrules/ | f38d8571fa06 | curl | 8.22.0-r0 | 4 |
| grafana/ | 121a7a9ece6d | curl | 8.22.0-r0 | 4 |
| library/ | 1b766f17b840 | curl | 8.22.0-r0 | 4 |
| linuxserver/ | 4d9df314875e | curl | 8.22.0-r0 | 4 |
| pihole/ | f7d1be836e3b | curl | 8.22.0-r0 | 4 |
| rustfs/ | 41fe89380f41 | curl | 8.22.0-r0 | 4 |
| ghcr.io/ | 7f9a1d574958 | curl | no fix listed | 4 |
| alpine/ | 6f3b5029566d | curl | 8.22.0-r0 | 3 |
| decisionrules/ | 92e459f2c673 | curl | 8.22.0-r0 | 3 |
| fluent/ | d792375ca8e5 | curl | no fix listed | 3 |
| grafana/ | 7cb8c64c4d57 | curl | 8.22.0-r0 | 3 |
| natsio/ | ffce8bd10338 | curl | 8.22.0-r0 | 3 |
| vaultwarden/ | ebdfe70701c6 | curl | no fix listed | 3 |
| quay.io/ | dd3f47d5a5e4 | curl | no fix listed | 3 |
| quay.io/ | 522738d5285e | curl | 8.22.0-r0 | 3 |
| registry.gitlab.com/ | af0325804248 | curl | 8.22.0-r0 | 3 |
| alpine/ | 4f9488b7295b | curl | 8.22.0-r0 | 2 |
| alpine/ | 048f8d9c8cc7 | curl | 8.22.0-r0 | 2 |
| alpine/ | 9ccd82364762 | curl | 8.22.0-r0 | 2 |
| alpine/ | ec8f734b0a10 | curl | 8.22.0-r0 | 2 |
| cagriekin/ | 99e17aa165df | curl | no fix listed | 2 |
| clamav/ | 629a3050df6a | curl | 8.22.0-r0 | 2 |
| dunglas/ | 916834e49961 | curl | 8.22.0-r0 | 2 |
| fireflyiii/ | fe4ecec4c2ba | curl | no fix listed | 2 |
| fireflyiii/ | ab52bf932546 | curl | no fix listed | 2 |
| gisaia/ | 98213fa403ae | curl | 8.22.0-r0 | 2 |
| gisaia/ | 5abfe00317bf | curl | 8.22.0-r0 | 2 |
| gisaia/ | ac6564921994 | curl | 8.22.0-r0 | 2 |
| gisaia/ | 3700dcaf7a75 | curl | 8.22.0-r0 | 2 |
| gisaia/ | b83b3e067173 | curl | 8.22.0-r0 | 2 |
| gisaia/ | a35977a5bb7d | curl | 8.22.0-r0 | 2 |
| gisaia/ | 1a3cc43d822f | curl | 8.22.0-r0 | 2 |
| gisaia/ | ae525930b4b6 | curl | 8.22.0-r0 | 2 |
| gotenberg/ | 87c16b9f3642 | curl | no fix listed | 2 |
| gotenberg/ | f29984bd1e22 | curl | no fix listed | 2 |