CVE-2026-9079
CriticalAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.011
- 63rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 625
- of 17,787 indexed, latest versions
- Container images
- 449
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 625 of 17,787 indexed charts deploy, on 449 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+9 more | 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2 | 233 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more | 8.21.0-r0, 8.22.0-r0 | 216 |
- OSV records
- ALPINE-CVE-2026-9079DEBIAN-CVE-2026-9079UBUNTU-CVE-2026-9079
- Also known as
- USN-8487-1
Charts affected
625 by stars
Container images carrying it
449 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| devkrishan001/ | a0ad60836e6b | curl | 8.22.0-r0 | 1 |
| diygod/ | 1d4b508b6357 | curl | no fix listed | 1 |
| docuseal/ | 7493fd7f6728 | curl | 8.22.0-r0 | 1 |
| dokuwiki/ | f08ecfdda239 | curl | no fix listed | 1 |
| dragonflyoss/ | 6d710dc2bae0 | curl | 8.22.0-r0 | 1 |
| dunglas/ | 80fcb704a741 | curl | 8.22.0-r0 | 1 |
| eclipseaerios/ | e7f5ba0bc64d | curl | no fix listed | 1 |
| eclipseaerios/ | 3a8e4cf60629 | curl | 8.22.0-r0 | 1 |
| elautoestopista/ | 125ba620d528 | curl | 8.22.0-r0 | 1 |
| electriccoinco/ | 2ae3a551e111 | curl | no fix listed | 1 |
| emqx/ | 35b46f7aa7a0 | curl | no fix listed | 1 |
| epamedp/ | 49e8fe9c4855 | curl | 8.22.0-r0 | 1 |
| erikvl87/ | e1ea6a975388 | curl | 8.22.0-r0 | 1 |
| escaping/ | 87fa79255962 | curl | no fix listed | 1 |
| esphome/ | 4866347cb5b4 | curl | no fix listed | 1 |
| esphome/ | 85abea33854b | curl | no fix listed | 1 |
| espocrm/ | 1b5a24504ed9 | curl | no fix listed | 1 |
| espocrm/ | 4bd92daf5f0c | curl | 8.22.0-r0 | 1 |
| etherpad/ | b723fe5f2594 | curl | 8.22.0-r0 | 1 |
| ethpandaops/ | 1efa2fba6711 | curl | no fix listed | 1 |
| factoriotools/ | c6092b912bd1 | curl | no fix listed | 1 |
| factoriotools/ | e9227748c507 | curl | no fix listed | 1 |
| factoriotools/ | f7909f7361d6 | curl | no fix listed | 1 |
| filebrowser/ | dbac07403040 | curl | 8.22.0-r0 | 1 |
| fireflyiii/ | ae69fdd95cde | curl | no fix listed | 1 |
| fluent/ | a52221a2a3eb | curl | no fix listed | 1 |
| fluent/ | a941bdd5ca55 | curl | no fix listed | 1 |
| folioci/ | f0655a6a08fd | curl | 8.22.0-r0 | 1 |
| fosrl/ | c32ad797ab96 | curl | 8.22.0-r0 | 1 |
| geonode/ | 435cbc5f3f05 | curl | 8.21.0-r0 | 1 |
| gitea/ | 7940221bcfc9 | curl | 8.22.0-r0 | 1 |
| gitea/ | b5c35d6bdbb9 | curl | 8.22.0-r0 | 1 |
| gitea/ | c2a169c5e998 | curl | 8.22.0-r0 | 1 |
| gitea/ | 7d13848af126 | curl | 8.22.0-r0 | 1 |
| glpi/ | 4b681082a79e | curl | no fix listed | 1 |
| gomods/ | 0f61d1e62359 | curl | 8.22.0-r0 | 1 |
| gomods/ | 97cc113b34b0 | curl | 8.22.0-r0 | 1 |
| google/ | f7d3e6d6d4f4 | curl | 8.22.0-r0 | 1 |
| gotenberg/ | 206a6c708fc6 | curl | no fix listed | 1 |
| gotenberg/ | 67097317623a | curl | no fix listed | 1 |
| gotenberg/ | a40f92d7419a | curl | no fix listed | 1 |
| grafana/ | 0f86bada30d6 | curl | 8.22.0-r0 | 1 |
| grafana/ | 2d1f9ae67c17 | curl | 8.22.0-r0 | 1 |
| grafana/ | ba93c9d192e5 | curl | 8.22.0-r0 | 1 |
| graviteeio/ | 4140932887e0 | curl | 8.22.0-r0 | 1 |
| haproxytech/ | 7a3ef2dd8b5b | curl | 8.22.0-r0 | 1 |
| haproxytech/ | b9bffe2d0fd1 | curl | 8.22.0-r0 | 1 |
| haproxytech/ | d90f628d659e | curl | 8.22.0-r0 | 1 |
| hazelcast/ | f086bf0ecb23 | curl | 8.22.0-r0 | 1 |
| healthchecks/ | aa08a61b0dcf | curl | no fix listed | 1 |