CVE-2026-9080
HighAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.003
- 22nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 624
- of 17,787 indexed, latest versions
- Container images
- 447
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 624 of 17,787 indexed charts deploy, on 447 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+9 more | 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2 | 233 |
| curlapk | 8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+1 more | 8.21.0-r0, 8.22.0-r0 | 214 |
- OSV records
- ALPINE-CVE-2026-9080DEBIAN-CVE-2026-9080UBUNTU-CVE-2026-9080
- Also known as
- USN-8487-1
Charts affected
624 by stars
Container images carrying it
447 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| polyaxon/ | c186bd9834c0 | curl | no fix listed | 1 |
| postgis/ | 7e00e8c3539f | curl | no fix listed | 1 |
| powerdns/ | 33aadc74a8d6 | curl | no fix listed | 1 |
| pretix/ | 5df3b7aa852e | curl | no fix listed | 1 |
| prodrigestivill/ | f70742ebe42b | curl | no fix listed | 1 |
| qjoly/ | ec94d3bdc035 | curl | no fix listed | 1 |
| reallibrephotos/ | 98a13dabbadc | curl | no fix listed | 1 |
| redocly/ | 2e26bb660574 | curl | 8.22.0-r0 | 1 |
| redpandadata/ | 468bd13a9f2b | curl | no fix listed | 1 |
| reportportal/ | 06cdf299b397 | curl | 8.22.0-r0 | 1 |
| robiningelbrecht/ | 40842cdfd616 | curl | 8.22.0-r0 | 1 |
| rommapp/ | 3512f2ca4557 | curl | 8.22.0-r0 | 1 |
| roundcube/ | 17d9d9580962 | curl | no fix listed | 1 |
| rustfs/ | 3c2d55977829 | curl | 8.22.0-r0 | 1 |
| rustfs/ | 7d49faa88c04 | curl | 8.22.0-r0 | 1 |
| scholtz2/ | 3a3b3d3277d2 | curl | 8.18.0-1ubuntu2.2 | 1 |
| scholtz2/ | 6770214bc881 | curl | 8.18.0-1ubuntu2.2 | 1 |
| securecodebox/ | afcefbd56d61 | curl | 8.22.0-r0 | 1 |
| serversideup/ | 8f8c2f010ac5 | curl | no fix listed | 1 |
| siakhooi/ | f1f4b5b1b870 | curl | 8.22.0-r0 | 1 |
| signalen/ | 1ab79cb7fe21 | curl | 8.22.0-r0 | 1 |
| sissbruecker/ | 0c0a9a04c7eb | curl | no fix listed | 1 |
| softwaremill/ | 845b5e8f8056 | curl | 8.18.0-1ubuntu2.2 | 1 |
| sonroyaalmerol/ | 3f60f3abe990 | curl | no fix listed | 1 |
| sslhep/ | 1d12f943cec5 | curl | no fix listed | 1 |
| sslhep/ | e7aff7f97b89 | curl | no fix listed | 1 |
| sslhep/ | b01b8ee966ed | curl | no fix listed | 1 |
| sslhep/ | 0e4175a4e1eb | curl | no fix listed | 1 |
| sslhep/ | 671980005c57 | curl | no fix listed | 1 |
| sslhep/ | 596db2abdd09 | curl | no fix listed | 1 |
| sslhep/ | 54aaf1721d03 | curl | no fix listed | 1 |
| sslhep/ | 2cb88ceab5bb | curl | no fix listed | 1 |
| sslhep/ | c284442b44e3 | curl | no fix listed | 1 |
| stalwartlabs/ | 25001929f36a | curl | no fix listed | 1 |
| stalwartlabs/ | 74ca4f7f6885 | curl | no fix listed | 1 |
| stashapp/ | df744af5a0c9 | curl | 8.22.0-r0 | 1 |
| supabase/ | 49bfe526f1b4 | curl | no fix listed | 1 |
| supabase/ | f371b5f3f2ac | curl | 8.22.0-r0 | 1 |
| supabase/ | d3aa0c86c7b3 | curl | no fix listed | 1 |
| syncthing/ | 7c60eb0ec887 | curl | 8.22.0-r0 | 1 |
| tautulli/ | 670e68dd9efc | curl | no fix listed | 1 |
| temporalio/ | cfde8170c92f | curl | 8.22.0-r0 | 1 |
| temporalio/ | f14912b699cf | curl | 8.22.0-r0 | 1 |
| tenureai/ | 5f5b222df9a5 | curl | no fix listed | 1 |
| thijsvanloef/ | 401d3eb5c053 | curl | no fix listed | 1 |
| thijsvanloef/ | b4ac9ee22483 | curl | no fix listed | 1 |
| thingsboard/ | b5a9c1addf80 | curl | no fix listed | 1 |
| thingsboard/ | 70661025dba5 | curl | no fix listed | 1 |
| tinymediamanager/ | 2b34dc85099e | curl | no fix listed | 1 |
| tombursch/ | b48e4ab727cd | curl | no fix listed | 1 |