CVE-2026-9079
CriticalAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.011
- 63rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 635
- of 17,787 indexed, latest versions
- Container images
- 461
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 635 of 17,787 indexed charts deploy, on 461 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+9 more | 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2 | 243 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more | 8.21.0-r0, 8.22.0-r0 | 218 |
- OSV records
- ALPINE-CVE-2026-9079DEBIAN-CVE-2026-9079UBUNTU-CVE-2026-9079
- Also known as
- USN-8487-1
Charts affected
635 by stars
Container images carrying it
461 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| haproxytech/ | d90f628d659e | curl | 8.22.0-r0 | 1 |
| hazelcast/ | f086bf0ecb23 | curl | 8.22.0-r0 | 1 |
| healthchecks/ | aa08a61b0dcf | curl | no fix listed | 1 |
| heartexlabs/ | aa461572e8f9 | curl | 8.22.0-r0 | 1 |
| helmforge/ | 61f759a1421f | curl | no fix listed | 1 |
| helmforge/ | fcb7017327d6 | curl | no fix listed | 1 |
| helmforge/ | 7ba0d47b943f | curl | 8.22.0-r0 | 1 |
| hiboxsystems/ | b59f01bc0418 | curl | no fix listed | 1 |
| homeassistant/ | 5a531753cea9 | curl | 8.21.0-r0 | 1 |
| hwdsl2/ | 2e939ffe5913 | curl | 8.22.0-r0 | 1 |
| instill/ | c4a393e601ed | curl | no fix listed | 1 |
| instill/ | ebe12f77a3f9 | curl | no fix listed | 1 |
| instill/ | e980125e5ba5 | curl | no fix listed | 1 |
| inventree/ | a946ec09da3e | curl | no fix listed | 1 |
| ixsystems/ | 19c218455cd2 | curl | no fix listed | 1 |
| jellyfin/ | 1694ff069f0c | curl | no fix listed | 1 |
| jellyfin/ | 17285f9cce63 | curl | no fix listed | 1 |
| jellyfin/ | 333b64771663 | curl | no fix listed | 1 |
| jertel/ | 3cbf63f9b7dc | curl | no fix listed | 1 |
| jesec/ | c887dad96b40 | curl | 8.21.0-r0 | 1 |
| jupyterjsc/ | aea53b13f235 | curl | 8.22.0-r0 | 1 |
| kenchrcum/ | 12fb213debf1 | curl | 8.22.0-r0 | 1 |
| kenchrcum/ | c326e28a8f5f | curl | 8.22.0-r0 | 1 |
| kitware/ | d7767d9b9da4 | curl | no fix listed | 1 |
| kixote/ | 4e9dff179519 | curl | no fix listed | 1 |
| kixote/ | 628f79a08cc7 | curl | no fix listed | 1 |
| kubevirtmanager/ | 1b98f1b5977a | curl | 8.22.0-r0 | 1 |
| langgenius/ | 750e1111426e | curl | no fix listed | 1 |
| lbenicio/ | 732f9003de33 | curl | 8.22.0-r0 | 1 |
| library/ | ac978b783657 | curl | no fix listed | 1 |
| library/ | 13ba145cba2f | curl | 8.22.0-r0 | 1 |
| library/ | 834468128c76 | curl | 8.22.0-r0 | 1 |
| library/ | 512690a56605 | curl | no fix listed | 1 |
| library/ | 8e6bdd396496 | curl | no fix listed | 1 |
| library/ | b7faa1653c39 | curl | no fix listed | 1 |
| library/ | de4ad9389386 | curl | no fix listed | 1 |
| library/ | 1881968aff6f | curl | no fix listed | 1 |
| library/ | 2f07d83bf561 | curl | 8.22.0-r0 | 1 |
| library/ | 5616878291a2 | curl | 8.22.0-r0 | 1 |
| library/ | a8b39bd9cf0f | curl | 8.22.0-r0 | 1 |
| library/ | f5d1cc40abc1 | curl | no fix listed | 1 |
| library/ | 59fa733c9af6 | curl | no fix listed | 1 |
| library/ | 54451ecb8ab3 | curl | 8.22.0-r0 | 1 |
| library/ | 70c9cc675605 | curl | no fix listed | 1 |
| library/ | da5aee29682d | curl | no fix listed | 1 |
| library/ | 04ac44a2595b | curl | no fix listed | 1 |
| library/ | ad4a8bae2eb4 | curl | no fix listed | 1 |
| library/ | f73396626d2f | curl | no fix listed | 1 |
| librenms/ | 8194a4a9ff49 | curl | 8.22.0-r0 | 1 |
| linuxserver/ | a20fb11a440d | curl | 8.22.0-r0 | 1 |