StackRadar

CVE-2026-8286

High

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,802
of 17,787 indexed, latest versions
Container images
1,661
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security, bug fix, and enhancement update

Carried by container images the latest versions of 1,802 of 17,787 indexed charts deploy, on 1,661 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16+103 more7.35.0-1ubuntu2.20+esm20, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4+5 more1,221
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+23 more0:7.61.1-34.el8_10.13225
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0215
OSV records
ALPINE-CVE-2026-8286DEBIAN-CVE-2026-8286RHSA-2026:57462RLSA-2026:57462UBUNTU-CVE-2026-8286ECHO-6486-9a91-3077
Also known as
USN-8487-1

Charts affected

1,802 by stars
ChartLatestAffected imagesRadar Score
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
curl@7.88.1-10+deb12u1
no fix listed

Open the chart page →

5,657
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.13

Open the chart page →

2,903
appwriteappwrite-helmVerified publisher1.3.22 of 8See more

appwrite appwrite-helm 1.3.2

2 of the 8 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
curl@8.17.0-r1
8.22.0-r0
clamav/clamav:1.0dd0d9cc746af
curl@8.20.0-r1
8.21.0-r0

Open the chart page →

9,847
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
curl@8.14.1-2
no fix listed

Open the chart page →

7,489
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

7,300
arlas-aiasarlas-stackVerified publisher28.8.011 of 22See more

arlas-aias arlas-stack 28.8.0

11 of the 22 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
curl@7.88.1-10+deb12u12
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
curl@7.88.1-10+deb12u12
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
curl@7.88.1-10+deb12u8
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
curl@7.88.1-10+deb12u12
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
curl@7.88.1-10+deb12u12
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
curl@7.88.1-10+deb12u12
no fix listed
gisaia/arlas-fam-wui:0.18.13700dcaf7a75
curl@8.20.0-r0
8.22.0-r0
gisaia/arlas-wui:28.0.3b83b3e067173
curl@8.19.0-r0
8.22.0-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
curl@8.19.0-r0
8.22.0-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
curl@8.19.0-r0
8.22.0-r0
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

40,238
arlas-uisarlas-stackVerified publisher28.8.04 of 4See more

arlas-uis arlas-stack 28.8.0

4 of the 4 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
gisaia/arlas-fam-wui:0.18.13700dcaf7a75
curl@8.20.0-r0
8.22.0-r0
gisaia/arlas-wui:28.0.3b83b3e067173
curl@8.19.0-r0
8.22.0-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
curl@8.19.0-r0
8.22.0-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

2,985
titilerarlas-stackVerified publisher28.8.01 of 1See more

titiler arlas-stack 28.8.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,445
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.25+esm4

Open the chart page →

23,353
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.25+esm4
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.25+esm4

Open the chart page →

22,568
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.13
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.13

Open the chart page →

14,728
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
curl@7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.19+esm16
hyperledger/fabric-couchdb:0.4.15f6c724592abf
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm16

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
curl@7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.19+esm16
hyperledger/fabric-couchdb:0.4.15f6c724592abf
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm16

Open the chart page →

77,706
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm4

Open the chart page →

9,369
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.13

Open the chart page →

13,352
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25

Open the chart page →

10,061
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

18,277
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

8,032
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
curl@7.68.0-1ubuntu2.19
7.68.0-1ubuntu2.25+esm4

Open the chart page →

7,936
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm9

Open the chart page →

5,363
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
curl@7.88.1-10+deb12u1
no fix listed
library/mongo:4.4.66efa05203990
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm9

Open the chart page →

45,363
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.25+esm4
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

13,913
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.25
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

32,501
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

9,412
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25

Open the chart page →

6,908
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
curl@7.88.1-10+deb12u4
no fix listed

Open the chart page →

6,297
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

7,152
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
curl@7.88.1-10+deb12u12
no fix listed
kuzwolka/aws9:news3e8880fbbb96
curl@7.88.1-10+deb12u12
no fix listed
kuzwolka/aws9:blog4a7707410bf1
curl@7.88.1-10+deb12u12
no fix listed
kuzwolka/aws9:shop84a9d9766345
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

18,344
aws-web-service-proxifiedaws-web-service-proxified1.8.01 of 2See more

aws-web-service-proxified aws-web-service-proxified 1.8.0

1 of the 2 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,009
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25

Open the chart page →

3,268
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
infiniflow/infinity:v0.7.0992c87a68612
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.25

Open the chart page →

5,823
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
curl@8.14.1-2+deb13u2
no fix listed

Open the chart page →

2,738
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
curl@7.88.1-10+deb12u4
no fix listed

Open the chart page →

6,297
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm4
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm4
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.25+esm4

Open the chart page →

20,671
my-nginx-appbassant-nginx-app0.1.01 of 1See more

my-nginx-app bassant-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,028
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

1,901
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm4
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm9

Open the chart page →

20,190
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.25

Open the chart page →

7,190
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

5,059
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm9

Open the chart page →

22,891
tenzu-frontbiru-scop3.1.01 of 1See more

tenzu-front biru-scop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

845
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

10,145
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.2.6a52221a2a3eb
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

9,521
blackduck-alertblackduck8.4.02 of 4See more

blackduck-alert blackduck 8.4.0

2 of the 4 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
curl@8.17.0-r1
8.22.0-r0
blackducksoftware/blackduck-alert-rabbitmq:8.4.08f422b18d171
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

4,292
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.25+esm4

Open the chart page →

13,459
bluespacebluespace0.3.01 of 1See more

bluespace bluespace 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.25+esm4

Open the chart page →

15,253
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
curl@7.88.1-10+deb12u12
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

26,996
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-8286.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
library/cassandra:3.11.65aa8400b4b3b
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm9

Open the chart page →

19,229

Container images carrying it

1,661 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
byjg/easy-haproxy:6.1.1230fdb7b00ae
curl@8.20.0-r1
8.21.0-r0
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
curl@7.88.1-10+deb12u8
no fix listed
1
cars10/elasticvue:1.15.0efddf4fa0fd8
curl@8.17.0-r1
8.22.0-r0
1
casbin/casdoor:3.62.17729da148c61
curl@8.19.0-r0
8.22.0-r0
1
casbin/casdoor:3.62.0e08231f16c00
curl@8.19.0-r0
8.22.0-r0
1
castlemock/castlemock:latestb7f3f1527ba9
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
castopod/castopod:1.12.101fd37280cbb2
curl@7.88.1-10+deb12u7
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
curl@8.14.1-2+deb13u2
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
curl@7.81.0-1ubuntu1.24
7.81.0-1ubuntu1.25
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
curl@7.35.0-1ubuntu2.20
7.35.0-1ubuntu2.20+esm20
1
chetangautamm/repo:sipp.v3e7f7049e1544
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.25+esm4
1
cheveo/azp-agent:1.0.282240f890884
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
cheyang/distributed-tf:1.6.046cc34755493
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.19+esm16
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
curl@8.14.1-2+deb13u2
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
curl@8.14.1-2+deb13u3
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
circleci/runner:launch-agent9bdc62f02162
curl@7.68.0-1ubuntu2.24
7.68.0-1ubuntu2.25+esm4
1
ckan/ckan-base:2.12.087ecf3f27ad6
curl@7.88.1-10+deb12u15
no fix listed
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.25
1
ckulka/baikal:0.10.1-nginx434bdd162247
curl@7.88.1-10+deb12u12
no fix listed
1
clamav/clamav:1.0dd0d9cc746af
curl@8.20.0-r1
8.21.0-r0
1
cloudtooling/moodle:5.2.3f4f04e0fc401
curl@7.88.1-10+deb12u15
no fix listed
1
cloudve/ttyd:latestd79c1c5881c0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm9
1
cm2network/squad:latest8cba47f53df5
curl@8.14.1-2+deb13u2
no fix listed
1
cockroachdb/cockroach:v22.2.91116820f4134
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.13
1
cockroachdb/cockroach-operator:v2.1.0983312754620
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.13
1
coderenvs/coder-service:1.44.61deffc4670e6
curl@7.61.1-33.el8_9.5
0:7.61.1-34.el8_10.13
1
coderenvs/timescale:1.44.676fd37fe6830
curl@7.61.1-33.el8_9.5
0:7.61.1-34.el8_10.13
1
collabora/code:24.04.13.2.101dc4ab83977
curl@7.88.1-10+deb12u8
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
curl@7.88.1-10+deb12u5
no fix listed
1
conductoross/conductor:3.31.09fba127693e6
curl@8.14.1-2+deb13u3
no fix listed
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.13
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.13
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.13
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.13
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.13
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.13
1
confluentinc/cp-kafka:7.5.1dc9b972db002
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.13
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.13
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.13
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.13
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.13
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.13
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.13
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.13
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.13
1
consensys/teku:25.4.1bf6ecd2ea716
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
curl@7.88.1-10+deb12u7
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
curl@7.81.0-1ubuntu1.21
7.81.0-1ubuntu1.25
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.