StackRadar

CVE-2026-9080

High

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
624
of 17,787 indexed, latest versions
Container images
447
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 624 of 17,787 indexed charts deploy, on 447 images.

Affected packageAffected versionsFixed inImages
curldeb8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+9 more8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2233
curlapk8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+1 more8.21.0-r0, 8.22.0-r0214
OSV records
ALPINE-CVE-2026-9080DEBIAN-CVE-2026-9080UBUNTU-CVE-2026-9080
Also known as
USN-8487-1

Charts affected

624 by stars
ChartLatestAffected imagesRadar Score
myfirstcharttest-helm-charts0.2.01 of 1See more

myfirstchart test-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
voyagertibuntu1.2.01 of 1See more

voyager tibuntu 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
ghcr.io/aeharding/voyager:latest779759172676
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,825
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

4,423
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,296
traefik-external-dns-controllertraefik-external-dns-operator2.2.01 of 1See more

traefik-external-dns-controller traefik-external-dns-operator 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,484
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,675
ats-ingresstrafficserver-ingress-controller0.1.01 of 1See more

ats-ingress trafficserver-ingress-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
ghcr.io/apache/ats-ingress:latest2d4d776f6362
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

414
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

5,550
applicationuniversal-helm-chartVerified publisher0.4.31 of 1See more

application universal-helm-chart 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

2,620
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,961
argus-test-envvk-helm-charts2.0.01 of 1See more

argus-test-env vk-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

3,911
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
curl@8.14.1-2+deb13u3
no fix listed

Open the chart page →

2,018
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

2,476
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

5,459
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
curl@8.19.0-r0
8.22.0-r0

Open the chart page →

1,639
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

5,560
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
curl@8.20.0-r0
8.22.0-r0

Open the chart page →

1,042
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.22.0-r0

Open the chart page →

1,571
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-9080.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
curl@8.14.1-2+deb13u4
no fix listed

Open the chart page →

1,827

Container images carrying it

447 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
curl@8.14.1-2+deb13u4
no fix listed
1
postgis/postgis:18-3.67e00e8c3539f
curl@8.14.1-2+deb13u4
no fix listed
1
powerdns/pdns-recursor-54:5.4.533aadc74a8d6
curl@8.14.1-2+deb13u4
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
curl@8.14.1-2+deb13u4
no fix listed
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
curl@8.14.1-2
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
curl@8.14.1-2+deb13u4
no fix listed
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
curl@8.14.1-2+deb13u3
no fix listed
1
redocly/redoc:latest2e26bb660574
curl@8.19.0-r0
8.22.0-r0
1
redpandadata/redpanda:latest468bd13a9f2b
curl@8.14.1-2+deb13u4
no fix listed
1
reportportal/k8s-wait-for:latest06cdf299b397
curl@8.19.0-r0
8.22.0-r0
1
robiningelbrecht/strava-statistics:v5.0.040842cdfd616
curl@8.19.0-r0
8.22.0-r0
1
rommapp/romm:5.2.03512f2ca4557
curl@8.17.0-r1
8.22.0-r0
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
curl@8.14.1-2+deb13u3
no fix listed
1
rustfs/rustfs:1.0.0-beta.13c2d55977829
curl@8.17.0-r1
8.22.0-r0
1
rustfs/rustfs:1.0.0-alpha.947d49faa88c04
curl@8.17.0-r1
8.22.0-r0
1
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
curl@8.18.0-1ubuntu2.1
8.18.0-1ubuntu2.2
1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
curl@8.18.0-1ubuntu2.1
8.18.0-1ubuntu2.2
1
securecodebox/persistence-elastic-dashboard-importer:5.7.0afcefbd56d61
curl@8.17.0-r1
8.22.0-r0
1
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
curl@8.14.1-2+deb13u4
no fix listed
1
siakhooi/query:1.0.0f1f4b5b1b870
curl@8.17.0-r1
8.22.0-r0
1
signalen/frontend:2.27.81ab79cb7fe21
curl@8.19.0-r0
8.22.0-r0
1
sissbruecker/linkding:1.46.20c0a9a04c7eb
curl@8.14.1-2+deb13u4
no fix listed
1
softwaremill/bootzooka:latest845b5e8f8056
curl@8.18.0-1ubuntu2.1
8.18.0-1ubuntu2.2
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
curl@8.14.1-2+deb13u2
no fix listed
1
sslhep/servicex_app:v1.8.51d12f943cec5
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
curl@8.14.1-2+deb13u4
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
curl@8.14.1-2+deb13u4
no fix listed
1
stalwartlabs/stalwart:v0.16.1425001929f36a
curl@8.14.1-2+deb13u4
no fix listed
1
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
curl@8.14.1-2+deb13u4
no fix listed
1
stashapp/stash:v0.31.1df744af5a0c9
curl@8.17.0-r1
8.22.0-r0
1
supabase/logflare:latest49bfe526f1b4
curl@8.14.1-2+deb13u4
no fix listed
1
supabase/postgres:17.6.1.136f371b5f3f2ac
curl@8.19.0-r0
8.22.0-r0
1
supabase/realtime:latestd3aa0c86c7b3
curl@8.14.1-2+deb13u4
no fix listed
1
syncthing/syncthing:2.1.07c60eb0ec887
curl@8.17.0-r1
8.22.0-r0
1
tautulli/tautulli:latest670e68dd9efc
curl@8.14.1-2+deb13u4
no fix listed
1
temporalio/admin-tools:1.28cfde8170c92f
curl@8.17.0-r1
8.22.0-r0
1
temporalio/auto-setup:1.29.7f14912b699cf
curl@8.19.0-r0
8.22.0-r0
1
tenureai/tenure:v1.0.285f5b222df9a5
curl@8.14.1-2+deb13u3+dhi3
no fix listed
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
curl@8.14.1-2+deb13u2
no fix listed
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
curl@8.14.1-2+deb13u2
no fix listed
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
curl@8.14.1-2+deb13u4
no fix listed
1
thingsboard/tbmq-node:2.4.070661025dba5
curl@8.14.1-2+deb13u4
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
curl@8.14.1-2+deb13u2
no fix listed
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
curl@8.14.1-2+deb13u2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.