CVE-2026-9080
HighAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.003
- 22nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 632
- of 17,781 indexed, latest versions
- Container images
- 456
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 632 of 17,781 indexed charts deploy, on 456 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+9 more | 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2 | 240 |
| curlapk | 8.17.0-r1, 8.18.0-r0, 8.19.0-r0, 8.20.0-r0+1 more | 8.21.0-r0, 8.22.0-r0 | 216 |
- OSV records
- ALPINE-CVE-2026-9080DEBIAN-CVE-2026-9080UBUNTU-CVE-2026-9080
- Also known as
- USN-8487-1
Charts affected
632 by stars
Container images carrying it
456 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 05b8cb60c354 | curl | no fix listed | 106 |
| library/ | d5792f71a949 | curl | no fix listed | 23 |
| jenkins/ | c1e4c349365f | curl | no fix listed | 13 |
| jellyfin/ | aefb67e6a7ff | curl | no fix listed | 7 |
| library/ | 3a8a8d6b5289 | curl | no fix listed | 7 |
| vaultwarden/ | 094b5689ed81 | curl | no fix listed | 7 |
| ghcr.io/ | aa810a36942c | curl | no fix listed | 7 |
| library/ | 5a93c470ae82 | curl | no fix listed | 6 |
| nginxinc/ | 0c79d56aee56 | curl | 8.22.0-r0 | 6 |
| library/ | 979c38c2228d | curl | no fix listed | 5 |
| registry.k8s.io/ | 594ceea76b01 | curl | 8.22.0-r0 | 5 |
| grafana/ | 121a7a9ece6d | curl | 8.21.0-r0 | 4 |
| library/ | 1b766f17b840 | curl | 8.21.0-r0 | 4 |
| fluent/ | d792375ca8e5 | curl | no fix listed | 3 |
| localstack/ | 4aef81c53168 | curl | no fix listed | 3 |
| natsio/ | ffce8bd10338 | curl | 8.22.0-r0 | 3 |
| vaultwarden/ | ebdfe70701c6 | curl | no fix listed | 3 |
| quay.io/ | 522738d5285e | curl | 8.22.0-r0 | 3 |
| alpine/ | 048f8d9c8cc7 | curl | 8.21.0-r0 | 2 |
| alpine/ | 9ccd82364762 | curl | 8.22.0-r0 | 2 |
| alpine/ | ec8f734b0a10 | curl | 8.22.0-r0 | 2 |
| cagriekin/ | 99e17aa165df | curl | no fix listed | 2 |
| clamav/ | 629a3050df6a | curl | 8.22.0-r0 | 2 |
| dunglas/ | 916834e49961 | curl | 8.22.0-r0 | 2 |
| fireflyiii/ | fe4ecec4c2ba | curl | no fix listed | 2 |
| fireflyiii/ | ab52bf932546 | curl | no fix listed | 2 |
| gisaia/ | 3700dcaf7a75 | curl | 8.22.0-r0 | 2 |
| gisaia/ | b83b3e067173 | curl | 8.22.0-r0 | 2 |
| gisaia/ | a35977a5bb7d | curl | 8.22.0-r0 | 2 |
| gisaia/ | 1a3cc43d822f | curl | 8.22.0-r0 | 2 |
| gotenberg/ | 87c16b9f3642 | curl | no fix listed | 2 |
| gotenberg/ | f29984bd1e22 | curl | no fix listed | 2 |
| grafana/ | 2175aaa91c96 | curl | 8.22.0-r0 | 2 |
| grafana/ | 9e1e77ade304 | curl | 8.22.0-r0 | 2 |
| grafana/ | e932bd6ed0e0 | curl | 8.22.0-r0 | 2 |
| graviteeio/ | 05fd67a93056 | curl | no fix listed | 2 |
| graviteeio/ | 27374522cd04 | curl | no fix listed | 2 |
| infisical/ | 02082bf13163 | curl | no fix listed | 2 |
| jenkins/ | c4098086090c | curl | no fix listed | 2 |
| jupyterhub/ | 69a7170eeeda | curl | 8.22.0-r0 | 2 |
| library/ | 04907bdd423b | curl | no fix listed | 2 |
| library/ | 5f5c8640aae0 | curl | 8.22.0-r0 | 2 |
| library/ | df7f1c2fb114 | curl | 8.22.0-r0 | 2 |
| library/ | b97df9e0e1ee | curl | no fix listed | 2 |
| library/ | 6e23479198b9 | curl | no fix listed | 2 |
| library/ | 9dd288848f44 | curl | no fix listed | 2 |
| library/ | f474a901faec | curl | no fix listed | 2 |
| library/ | 30bff39330d1 | curl | no fix listed | 2 |
| metabase/ | 9491ed11c901 | curl | 8.22.0-r0 | 2 |
| moby/ | 504731e577c2 | curl | 8.22.0-r0 | 2 |