StackRadar

CVE-2026-8925

Critical

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
523
of 17,787 indexed, latest versions
Container images
480
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 523 of 17,787 indexed charts deploy, on 480 images.

Affected packageAffected versionsFixed inImages
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+24 more7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2263
curlapk8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+1 more8.21.0-r0, 8.22.0-r0217
OSV records
ALPINE-CVE-2026-8925UBUNTU-CVE-2026-8925
Also known as
USN-8487-1

Charts affected

523 by stars
ChartLatestAffected imagesRadar Score
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

8,251
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,116
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,043
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

4,213
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.25

Open the chart page →

20,362
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,826
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,676
ats-ingresstrafficserver-ingress-controller0.1.01 of 1See more

ats-ingress trafficserver-ingress-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/apache/ats-ingress:latest2d4d776f6362
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

414
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

5,599
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,622
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
curl@8.5.0-2ubuntu10.1
8.5.0-2ubuntu10.10

Open the chart page →

45,392
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

9,396
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10

Open the chart page →

4,360
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

13,563
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10

Open the chart page →

7,696
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.25

Open the chart page →

6,272
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

5,472
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25

Open the chart page →

9,296
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
curl@8.5.0-2ubuntu10.8
8.5.0-2ubuntu10.10

Open the chart page →

2,229
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,640
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25

Open the chart page →

14,172
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-8925.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571

Container images carrying it

480 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
krontechnology/aapm-agent:1.8.41cc7d5be6529
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.25
1
krontechnology/aapm-service:1.1.39dd602db8baa
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.25
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
curl@8.17.0-r1
8.22.0-r0
1
kusionstack/kusion:v0.14.0126c8f0b0976
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
curl@7.81.0-1ubuntu1.16
7.81.0-1ubuntu1.25
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.10
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
lbenicio/stremio-web:latest732f9003de33
curl@8.17.0-r1
8.22.0-r0
1
library/caddy:latest13ba145cba2f
curl@8.19.0-r0
8.22.0-r0
1
library/caddy:2.11.2-alpine834468128c76
curl@8.17.0-r1
8.22.0-r0
1
library/flink:1.14.6-scala_2.122461f02672b3
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.25
1
library/mongo:7.0.140032d2ca20db
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.25
1
library/mongo:6.0.12646902910d6a
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
library/mongo:7.0.28-jammy88785f6f665a
curl@7.81.0-1ubuntu1.21
7.81.0-1ubuntu1.25
1
library/mongo:7.0.12ae1cf99fa7bf
curl@7.81.0-1ubuntu1.17
7.81.0-1ubuntu1.25
1
library/mongo:8.0.11dca8d11fe467
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
library/nginx:1.31.0-alpine2f07d83bf561
curl@8.19.0-r0
8.22.0-r0
1
library/nginx:1.29.8-alpine5616878291a2
curl@8.17.0-r1
8.22.0-r0
1
library/nginx:1.28-alpinea8b39bd9cf0f
curl@8.17.0-r1
8.22.0-r0
1
library/postgres:18.3-alpine54451ecb8ab3
curl@8.17.0-r1
8.22.0-r0
1
library/sonarqube:10.7.0-community0842dcd4c8f8
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.25
1
library/sonarqube:10.0.0-communityef9723cf4fe4
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.25
1
library/zookeeper:3.8-temurin55d1e5b2e601
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.25
1
library/zookeeper:3.9.4dfa9ba46d14b
curl@7.81.0-1ubuntu1.21
7.81.0-1ubuntu1.25
1
librenms/librenms:26.8.28194a4a9ff49
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/bazarr:latesta20fb11a440d
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/bookstack:26.05.202605282ebf97852661
curl@8.19.0-r0
8.22.0-r0
1
linuxserver/calibre-web:0.6.24241009026e6f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
linuxserver/code-server:4.10.1a5e43a05ae79
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.25
1
linuxserver/deluge:2.2.09505c64720af
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/foldingathome:7.6.219a997426d71e
curl@8.5.0-2ubuntu10.1
8.5.0-2ubuntu10.10
1
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
curl@8.20.0-r0
8.22.0-r0
1
linuxserver/prowlarr:2.4.0.5397-ls149a46d0ce0a823
curl@8.19.0-r0
8.22.0-r0
1
linuxserver/qbittorrent:5.2.2dd24a5f3db32
curl@8.19.0-r0
8.22.0-r0
1
linuxserver/sonarr:version-4.0.17.295202bc962946fe
curl@8.19.0-r0
8.22.0-r0
1
livekit/ingress:v1.2.21ab01641b366
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.25
1
loeken/sonarr:4.0.17b940520a2236
curl@8.19.0-r0
8.22.0-r0
1
m11s/decap-cms:0.2.11-s30cd6810c9885
curl@8.19.0-r0
8.22.0-r0
1
maponyacharles/sceptreai:seaweedfs-0.1.127c8a525f08e9
curl@8.20.0-r0
8.22.0-r0
1
maponyacharles/sceptreai:ui-0.1.127cd0f11c5e55
curl@8.20.0-r0
8.22.0-r0
1
mbround18/valheim:3.1.070bd4da591cd
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
mediagis/nominatim:5.3.27923a8e67197
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.10
1
mediagis/nominatim:4.2d0eae7b51374
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
metabase/metabase:v0.63.1.124f150effd484
curl@8.20.0-r0
8.22.0-r0
1
mlikiowa/napcat-docker:latest1336a777f9a4
curl@7.81.0-1ubuntu1.18
7.81.0-1ubuntu1.25
1
moby/buildkit:v0.33.06c2fa84a6b61
curl@8.20.0-r0
8.22.0-r0
1
moby/buildkit:v0.33.0-rootless80b15f0735e8
curl@8.20.0-r0
8.22.0-r0
1
moby/buildkit:v0.31.0a095b3d11ce1
curl@8.19.0-r0
8.22.0-r0
1
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
curl@8.17.0-r1
8.22.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.