StackRadar

CVE-2026-8925

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
523
of 17,787 indexed, latest versions
Container images
480
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 523 of 17,787 indexed charts deploy, on 480 images.

Affected packageAffected versionsFixed inImages
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+24 more7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2263
curlapk8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+1 more8.21.0-r0, 8.22.0-r0217
OSV records
ALPINE-CVE-2026-8925UBUNTU-CVE-2026-8925
Also known as
USN-8487-1

Charts affected

523 by stars
ChartLatestAffected imagesRadar Score
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

8,251
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,116
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,043
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

4,213
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.25

Open the chart page →

20,362
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,826
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,676
ats-ingresstrafficserver-ingress-controller0.1.01 of 1See more

ats-ingress trafficserver-ingress-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/apache/ats-ingress:latest2d4d776f6362
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

414
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

5,599
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,622
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
curl@8.5.0-2ubuntu10.1
8.5.0-2ubuntu10.10

Open the chart page →

45,392
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

9,396
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10

Open the chart page →

4,360
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

13,563
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

7,696
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.25

Open the chart page →

6,272
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

5,472
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

9,296
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10

Open the chart page →

2,229
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,640
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25

Open the chart page →

14,172
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571

Container images carrying it

480 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
2
ghcr.io/cinnyapp/cinny:v4.12.6a7805a8a60ff
curl@8.19.0-r0
8.22.0-r0
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.25
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
curl@8.20.0-r1
8.21.0-r0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
curl@8.20.0-r1
8.21.0-r0
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
curl@7.81.0-1ubuntu1.2
7.81.0-1ubuntu1.25
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
curl@8.17.0-r1
8.22.0-r0
2
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
curl@8.17.0-r1
8.22.0-r0
2
1dev/server:11.9.0cd5b12fe5471
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
curl@8.5.0-2ubuntu10.1
8.5.0-2ubuntu10.10
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
akeyless/base:latest759e4289fae8
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.10
1
aktosecurity/data-ingestion-service213aded7adc5
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
alpine/helm:4.1.0905a068da431
curl@8.18.0-r0
8.21.0-r0
1
alpine/k8s:1.36.244ef4942e171
curl@8.20.0-r1
8.21.0-r0
1
alpine/k8s:1.35.6b7a12c5ddf26
curl@8.20.0-r1
8.21.0-r0
1
alpine/k8s:1.35.5d870622d0040
curl@8.20.0-r1
8.21.0-r0
1
alpine/kubectl:1.36.01ee9df6316d4
curl@8.17.0-r1
8.22.0-r0
1
alpine/kubectl:1.35.0862d86046bbc
curl@8.17.0-r1
8.22.0-r0
1
alpine/kubectl:1.35.3c4a11ae9a1cb
curl@8.17.0-r1
8.22.0-r0
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
curl@8.5.0-2ubuntu10.4
8.5.0-2ubuntu10.10
1
apache/activemq-artemis:2.44.00305c26f19ed
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
apache/activemq-artemis:2.37.0bae523439ee3
curl@8.5.0-2ubuntu10.2
8.5.0-2ubuntu10.10
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
curl@7.81.0-1ubuntu1.21
7.81.0-1ubuntu1.25
1
apache/hertzbeat:1.8.075d48a62748f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
apache/nifi-registry:1.27.063b8e3e40742
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.25
1
apachepulsar/pulsar:3.0.79c9947de139d
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.25
1
apache/ranger:2.7.076c176e8a0e4
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
apache/rocketmq:5.3.0434d8398f996
curl@8.5.0-2ubuntu10.1
8.5.0-2ubuntu10.10
1
apache/rocketmq-exporter:0.0.2c8fb51195444
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
apache/skywalking-oap-server:9.2.0133d35d2c263
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.25
1
apache/skywalking-ui:9.2.0295f1dc87d98
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.25
1
appwrite/appwrite:1.9.01aaa70127114
curl@8.17.0-r1
8.22.0-r0
1
appwrite/appwrite:1.9.6adc7d0e7ec23
curl@8.19.0-r0
8.22.0-r0
1
appwrite/console:8.7.383dcdc8492ac6
curl@8.17.0-r1
8.22.0-r0
1
aquasec/trivy:0.69.3bcc376de8d77
curl@8.17.0-r1
8.22.0-r0
1
arunvelsriram/utils:latest655ad18fd8d6
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
assistiot/location_processing:lateste9bae124095f
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25
1
assistiot/open_api_backend:1.1.230812ba93555
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
atlassian/confluence-server:7.10.03b9222ab32ef
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25
1
atlassian/jira-software:8.14.037bc46cbec1a
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
atlassian/jira-software:9.7.264a75aa4ec4e
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
curl@8.17.0-r1
8.22.0-r0
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
curl@8.17.0-r1
8.22.0-r0
1
blackducksoftware/blackduck-alert-rabbitmq:8.4.08f422b18d171
curl@8.17.0-r1
8.22.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.