StackRadar

CVE-2026-8925

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
523
of 17,787 indexed, latest versions
Container images
480
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 523 of 17,787 indexed charts deploy, on 480 images.

Affected packageAffected versionsFixed inImages
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+24 more7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2263
curlapk8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+1 more8.21.0-r0, 8.22.0-r0217
OSV records
ALPINE-CVE-2026-8925UBUNTU-CVE-2026-8925
Also known as
USN-8487-1

Charts affected

523 by stars
ChartLatestAffected imagesRadar Score
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

8,251
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,116
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,043
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

4,213
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.25

Open the chart page →

20,362
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,826
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,676
ats-ingresstrafficserver-ingress-controller0.1.01 of 1See more

ats-ingress trafficserver-ingress-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/apache/ats-ingress:latest2d4d776f6362
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

414
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

5,599
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,622
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
curl@8.5.0-2ubuntu10.1
8.5.0-2ubuntu10.10

Open the chart page →

45,392
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

9,396
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10

Open the chart page →

4,360
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

13,563
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

7,696
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.25

Open the chart page →

6,272
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

5,472
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

9,296
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10

Open the chart page →

2,229
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,640
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25

Open the chart page →

14,172
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571

Container images carrying it

480 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10
1
ghcr.io/teq-cloud/iteq-web:0.3.3-beta0acbe2f2e1ea
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/timothepoznanski/poznote:6.80.0045035db3a20
curl@8.20.0-r0
8.22.0-r0
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
curl@8.5.0-2ubuntu10.5
8.5.0-2ubuntu10.10
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
curl@8.17.0-r1
8.22.0-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.10
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
quay.io/aerokube/keygen:1.0.1578934444f04
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.25
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.25
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
curl@8.19.0-r0
8.22.0-r0
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
curl@8.17.0-r1
8.22.0-r0
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.22.0-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
curl@8.20.0-r0
8.22.0-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
curl@8.17.0-r1
8.22.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.