StackRadar

CVE-2026-8286

High

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,803
of 17,790 indexed, latest versions
Container images
1,664
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security, bug fix, and enhancement update

Carried by container images the latest versions of 1,803 of 17,790 indexed charts deploy, on 1,664 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16+103 more7.35.0-1ubuntu2.20+esm20, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4+5 more1,228
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+23 more0:7.61.1-34.el8_10.13226
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0210
OSV records
ALPINE-CVE-2026-8286DEBIAN-CVE-2026-8286RHSA-2026:57462RLSA-2026:57462UBUNTU-CVE-2026-8286ECHO-6486-9a91-3077
Also known as
USN-8487-1

Charts affected

1,803 by stars
ChartLatestAffected imagesRadar Score
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.13

Open the chart page →

3,697
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,839

Container images carrying it

1,664 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
curl@8.19.0-r0
8.22.0-r0
2
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
curl@8.19.0-r0
8.22.0-r0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
curl@8.21.0-2~bpo13+1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
curl@8.21.0-2~bpo13+1
no fix listed
2
gradiant/ueransim:3.2.6015b30d5fa0f
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
2
grafana/grafana:12.3.12175aaa91c96
curl@8.17.0-r1
8.22.0-r0
2
grafana/grafana:12.3.39e1e77ade304
curl@8.17.0-r1
8.22.0-r0
2
grafana/grafana:12.4.1e932bd6ed0e0
curl@8.17.0-r1
8.22.0-r0
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
curl@8.14.1-2+deb13u4
no fix listed
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
curl@8.14.1-2+deb13u4
no fix listed
2
infisical/infisical:latest:v0.165.602082bf13163
curl@8.14.1-2+deb13u4
no fix listed
2
interlayhq/interbtc:latesta66d0e35e70f
curl@7.68.0-1ubuntu2.25
7.68.0-1ubuntu2.25+esm4
2
istio/kubectl:1.5.10dbb7726d1bf0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm9
2
istio/proxyv2:1.18.0757d28c24100
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.25
2
istio/proxyv2:1.10.3a78b7a165744
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm9
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
curl@7.88.1-10+deb12u4
no fix listed
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
curl@8.14.1-2+deb13u2
no fix listed
2
jupyterhub/configurable-http-proxy:5.3.0:latest69a7170eeeda
curl@8.19.0-r0
8.22.0-r0
2
kurento/kurento-media-server:latest03c0d34d0828
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
2
library/buildpack-deps:curl04907bdd423b
curl@8.14.1-2+deb13u4
no fix listed
2
library/caddy:2.11.4-alpine:2-alpine5f5c8640aae0
curl@8.19.0-r0
8.22.0-r0
2
library/caddy:latestdf7f1c2fb114
curl@8.19.0-r0
8.22.0-r0
2
library/cassandra:3.11.65aa8400b4b3b
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm9
2
library/cassandra:4.1.37cbcec0086ac
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
2
library/elasticsearch:7.17.35e6ac15bf6a5
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm4
2
library/elasticsearch:8.19.1289729a95066a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10
2
library/influxdb:2.7b8d940ca9376
curl@7.88.1-10+deb12u14
no fix listed
2
library/mongo:8.0.20098862b1339f
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10
2
library/mongo:5.041108d183e97
curl@7.68.0-1ubuntu2.25
7.68.0-1ubuntu2.25+esm4
2
library/mongo:4.2.358b25d51baa1
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm9
2
library/nginx:latest6e23479198b9
curl@8.14.1-2+deb13u2
no fix listed
2
library/nginx:1.27.098f8ec75657d
curl@7.88.1-10+deb12u6
no fix listed
2
library/nginx:1.29.49dd288848f44
curl@8.14.1-2+deb13u2
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
curl@7.88.1-10+deb12u8
no fix listed
2
library/python:3.7eedf63967cdb
curl@7.88.1-10+deb12u1
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
curl@8.14.1-2+deb13u4
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
curl@8.14.1-2+deb13u2
no fix listed
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm16
2
localstack/localstack-pro:latest4aef81c53168
curl@8.14.1-2+deb13u4
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
curl@7.88.1-10+deb12u14
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
curl@7.88.1-10+deb12u14
no fix listed
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
curl@7.68.0-1ubuntu2.2
7.68.0-1ubuntu2.25+esm4
2
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0
2
minio/operator:v4.3.754393e03f3b2
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.13
2
moby/buildkit:v0.32.2-rootless504731e577c2
curl@8.20.0-r0
8.22.0-r0
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
curl@7.88.1-10+deb12u6
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
curl@7.88.1-10+deb12u4
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
curl@7.88.1-10+deb12u4
no fix listed
2
nginxinc/nginx-unprivileged:stablecb92301e719d
curl@8.14.1-2+deb13u4
no fix listed
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.