CVE-2026-8286
HighAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.1
- base score, highest
- EPSS
- 0.003
- 24th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,812
- of 17,803 indexed, latest versions
- Container images
- 1,666
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: curl security, bug fix, and enhancement update
Carried by container images the latest versions of 1,812 of 17,803 indexed charts deploy, on 1,666 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 1:8.14.1-2+deb13u3+e1, 7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16+103 more | 7.35.0-1ubuntu2.20+esm20, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4+5 more | 1,229 |
| curlrpm | 7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+23 more | 0:7.61.1-34.el8_10.13 | 226 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more | 8.21.0-r0, 8.22.0-r0 | 211 |
- OSV records
- ALPINE-CVE-2026-8286DEBIAN-CVE-2026-8286RHSA-2026:57462RLSA-2026:57462UBUNTU-CVE-2026-8286ECHO-6486-9a91-3077
- Also known as
- USN-8487-1
Charts affected
1,812 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| Wordpresswordpress-mariadb | 1.0.2 | 1 of 2See more | 5,713 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,218 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,622 |
| xboardxboard | 0.2.0 | 1 of 1See more | 1,042 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,714 |
| xkopsxkops | 0.1.0 | 1 of 5See more | 13,813 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,861 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,861 |
| keycloakxzaks | 2.2.0 | 1 of 1See more | 6,017 |
| posthogzeet | 0.23.2 | 1 of 9See more | 3,697 |
| language-toolzekker6Verified publisher | 1.12.1 | 1 of 2See more | 1,565 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,861 |
Container images carrying it
1,666 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 28f263fe06f7 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 73ca19b41745 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | e3f80c0625aa | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | a56dfe91f5b1 | curl | 7.81.0-1ubuntu1.25 | 1 |
| ghcr.io/ | 916746209ac5 | curl | 7.81.0-1ubuntu1.25 | 1 |
| ghcr.io/ | 63873f3f698e | curl | 7.81.0-1ubuntu1.25 | 1 |
| ghcr.io/ | a3c27ee3fb2f | curl | no fix listed | 1 |
| ghcr.io/ | 86ab9effd1a5 | curl | no fix listed | 1 |
| ghcr.io/ | 6e04659a3baa | curl | no fix listed | 1 |
| ghcr.io/ | 8622ea9e43c0 | curl | no fix listed | 1 |
| ghcr.io/ | 1572e12bc93c | curl | no fix listed | 1 |
| ghcr.io/ | dbaa8527bf4c | curl | no fix listed | 1 |
| ghcr.io/ | 282f840612d9 | curl | no fix listed | 1 |
| ghcr.io/ | d19d886d5090 | curl | no fix listed | 1 |
| ghcr.io/ | 8e6a9516eac0 | curl | 7.58.0-2ubuntu3.24+esm9 | 1 |
| ghcr.io/ | e0f2f8c97598 | curl | 7.81.0-1ubuntu1.25 | 1 |
| ghcr.io/ | 5a6fe78d4d15 | curl | no fix listed | 1 |
| ghcr.io/ | 54082566391e | curl | no fix listed | 1 |
| ghcr.io/ | 7bff29dcec72 | curl | no fix listed | 1 |
| ghcr.io/ | ce435c77651e | curl | no fix listed | 1 |
| ghcr.io/ | fbba58ddb1a6 | curl | no fix listed | 1 |
| ghcr.io/ | 416e980f76a6 | curl | no fix listed | 1 |
| ghcr.io/ | 7dc0ee57b628 | curl | no fix listed | 1 |
| mcr.microsoft.com/ | cee0f4db03b5 | curl | 8.5.0-2ubuntu10.10 | 1 |
| public.ecr.aws/ | 5a5d32281374 | curl | no fix listed | 1 |
| public.ecr.aws/ | 1ed844ecab29 | curl | 8.5.0-2ubuntu10.10 | 1 |
| public.ecr.aws/ | ee9d973e3952 | curl | 7.81.0-1ubuntu1.25 | 1 |
| public.ecr.aws/ | af8cea3b8538 | curl | 8.14.1-2+e20 | 1 |
| public.ecr.aws/ | 70f191d0a80e | curl | 8.14.1-2+e20 | 1 |
| public.ecr.aws/ | b1493760c716 | curl | no fix listed | 1 |
| public.ecr.aws/ | 34823c8abe00 | curl | no fix listed | 1 |
| public.ecr.aws/ | 5cd62142d6ed | curl | no fix listed | 1 |
| public.ecr.aws/ | f8fb4eea4071 | curl | no fix listed | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | curl | no fix listed | 1 |
| public.ecr.aws/ | dc5a516c2333 | curl | no fix listed | 1 |
| public.ecr.aws/ | f7567ce3419d | curl | no fix listed | 1 |
| public.ecr.aws/ | 849e235e2d3e | curl | 0:7.61.1-34.el8_10.13 | 1 |
| public.ecr.aws/ | 86380a01587d | curl | 8.5.0-2ubuntu10.10 | 1 |
| public.ecr.aws/ | efcecf98b912 | curl | 7.58.0-2ubuntu3.24+esm9 | 1 |
| public.ecr.aws/ | 573779e57fae | curl | 7.68.0-1ubuntu2.25+esm4 | 1 |
| public.ecr.aws/ | f74851ce31f5 | curl | no fix listed | 1 |
| quay.io/ | 578934444f04 | curl | 7.81.0-1ubuntu1.25 | 1 |
| quay.io/ | 7302e0c8e5a7 | curl | 0:7.61.1-34.el8_10.13 | 1 |
| quay.io/ | 3b036692d546 | curl | 0:7.61.1-34.el8_10.13 | 1 |
| quay.io/ | 5b6701d8fb31 | curl | 7.81.0-1ubuntu1.25 | 1 |
| quay.io/ | 95b5cf7ba6fe | curl | 8.5.0-2ubuntu10.10 | 1 |
| quay.io/ | a36ab0c0860c | curl | 8.5.0-2ubuntu10.10 | 1 |
| quay.io/ | acaf37352569 | curl | 7.81.0-1ubuntu1.25 | 1 |
| quay.io/ | 3c56f354fac5 | curl | 8.22.0-r0 | 1 |
| quay.io/ | cdefc81c6b2e | curl | 0:7.61.1-34.el8_10.13 | 1 |