CVE-2026-9545
HighAdvisory
Published 24 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.003
- 19th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 633
- of 17,781 indexed, latest versions
- Container images
- 457
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 633 of 17,781 indexed charts deploy, on 457 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 8.14.1-2, 8.14.1-2+deb13u2, 8.14.1-2+deb13u3, 8.14.1-2+deb13u3+dhi3+9 more | 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2 | 240 |
| curlapk | 8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more | 8.21.0-r0, 8.22.0-r0 | 217 |
- OSV records
- ALPINE-CVE-2026-9545DEBIAN-CVE-2026-9545UBUNTU-CVE-2026-9545
- Also known as
- USN-8487-1
Charts affected
633 by stars
Container images carrying it
457 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| nginxinc/ | cb92301e719d | curl | no fix listed | 2 |
| openebs/ | 99f5116f5cb8 | curl | 8.22.0-r0 | 2 |
| polyaxon/ | eca6952b20e6 | curl | no fix listed | 2 |
| polyaxon/ | 024ff3fa775e | curl | no fix listed | 2 |
| requarks/ | 68f0d1848261 | curl | 8.22.0-r0 | 2 |
| syncthing/ | 775c4aac4862 | curl | 8.22.0-r0 | 2 |
| ghcr.io/ | a7805a8a60ff | curl | 8.22.0-r0 | 2 |
| ghcr.io/ | 612d76760b54 | curl | 8.21.0-r0 | 2 |
| ghcr.io/ | a1bc133af84e | curl | 8.21.0-r0 | 2 |
| registry.gitlab.com/ | b1198ea741d1 | curl | 8.22.0-r0 | 2 |
| registry.gitlab.com/ | 9bdb1062d960 | curl | 8.22.0-r0 | 2 |
| aapjeisbaas/ | 6b261abc7fb0 | curl | no fix listed | 1 |
| adamzammit/ | e75e2f455c8d | curl | no fix listed | 1 |
| agentarea/ | 9e15e16fa758 | curl | no fix listed | 1 |
| alpine/ | 905a068da431 | curl | 8.21.0-r0 | 1 |
| alpine/ | 44ef4942e171 | curl | 8.21.0-r0 | 1 |
| alpine/ | b7a12c5ddf26 | curl | 8.21.0-r0 | 1 |
| alpine/ | d870622d0040 | curl | 8.21.0-r0 | 1 |
| alpine/ | 1ee9df6316d4 | curl | 8.22.0-r0 | 1 |
| alpine/ | 862d86046bbc | curl | 8.22.0-r0 | 1 |
| alpine/ | c4a11ae9a1cb | curl | 8.22.0-r0 | 1 |
| antrea/ | ee9686bcefb8 | curl | no fix listed | 1 |
| apecloud/ | 8ac9947a2c84 | curl | no fix listed | 1 |
| appwrite/ | 1aaa70127114 | curl | 8.22.0-r0 | 1 |
| appwrite/ | adc7d0e7ec23 | curl | 8.22.0-r0 | 1 |
| appwrite/ | 3dcdc8492ac6 | curl | 8.22.0-r0 | 1 |
| aquasec/ | bcc376de8d77 | curl | 8.22.0-r0 | 1 |
| awesometechnologies/ | a1c1f4662875 | curl | 8.22.0-r0 | 1 |
| baserow/ | 7c00549b3a6f | curl | no fix listed | 1 |
| berkeleyskypilot/ | 3bc8bf8f4d83 | curl | no fix listed | 1 |
| berkeleyskypilot/ | 8da2f3cda472 | curl | no fix listed | 1 |
| blackducksoftware/ | 90cca32de2cc | curl | 8.22.0-r0 | 1 |
| blackducksoftware/ | 8f422b18d171 | curl | 8.22.0-r0 | 1 |
| boky/ | aafc77238423 | curl | no fix listed | 1 |
| budibase/ | 8d780b6ee602 | curl | no fix listed | 1 |
| byjg/ | 230fdb7b00ae | curl | 8.21.0-r0 | 1 |
| cars10/ | efddf4fa0fd8 | curl | 8.22.0-r0 | 1 |
| casbin/ | 7729da148c61 | curl | 8.22.0-r0 | 1 |
| casbin/ | e08231f16c00 | curl | 8.22.0-r0 | 1 |
| castopod/ | 4e4f0440520f | curl | no fix listed | 1 |
| chiefonboarding/ | 59bc7aa60fe7 | curl | no fix listed | 1 |
| chocobozzz/ | 052712130691 | curl | no fix listed | 1 |
| clamav/ | dd0d9cc746af | curl | 8.21.0-r0 | 1 |
| cm2network/ | 8cba47f53df5 | curl | no fix listed | 1 |
| conductoross/ | 9fba127693e6 | curl | no fix listed | 1 |
| cybrarist/ | e9e2447ac666 | curl | no fix listed | 1 |
| defectdojo/ | b140a89a34e2 | curl | no fix listed | 1 |
| dependencytrack/ | 1ba4f004e1ec | curl | no fix listed | 1 |
| dependencytrack/ | f1da63ed610a | curl | no fix listed | 1 |
| dependencytrack/ | 00560b57a6cf | curl | 8.22.0-r0 | 1 |