CVE-2026-9546
HighAdvisory
Published 3 Jul 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 41st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 125
- of 17,781 indexed, latest versions
- Container images
- 113
- deployed by those charts
- Fix available
- 1 of 1
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 125 of 17,781 indexed charts deploy, on 113 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 8.18.0-r0, 8.19.0-r0, 8.20.0-r0, 8.20.0-r1 | 8.21.0-r0, 8.22.0-r0 | 113 |
- OSV records
- ALPINE-CVE-2026-9546
Charts affected
125 by stars
Container images carrying it
113 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| linuxserver/ | a20fb11a440d | curl | 8.22.0-r0 | 1 |
| linuxserver/ | 2ebf97852661 | curl | 8.22.0-r0 | 1 |
| linuxserver/ | 9505c64720af | curl | 8.22.0-r0 | 1 |
| linuxserver/ | 4477fb1ce3ca | curl | 8.22.0-r0 | 1 |
| linuxserver/ | a46d0ce0a823 | curl | 8.22.0-r0 | 1 |
| linuxserver/ | dd24a5f3db32 | curl | 8.22.0-r0 | 1 |
| linuxserver/ | 02bc962946fe | curl | 8.22.0-r0 | 1 |
| loeken/ | b940520a2236 | curl | 8.22.0-r0 | 1 |
| m11s/ | 0cd6810c9885 | curl | 8.22.0-r0 | 1 |
| maponyacharles/ | 7c8a525f08e9 | curl | 8.22.0-r0 | 1 |
| maponyacharles/ | 7cd0f11c5e55 | curl | 8.22.0-r0 | 1 |
| metabase/ | 4f150effd484 | curl | 8.22.0-r0 | 1 |
| moby/ | 6c2fa84a6b61 | curl | 8.22.0-r0 | 1 |
| moby/ | 80b15f0735e8 | curl | 8.22.0-r0 | 1 |
| moby/ | a095b3d11ce1 | curl | 8.22.0-r0 | 1 |
| mrnim94/ | 86c4807a4bca | curl | 8.22.0-r0 | 1 |
| nginxinc/ | 6320020c7da8 | curl | 8.22.0-r0 | 1 |
| nocodb/ | 4b760f0d2547 | curl | 8.22.0-r0 | 1 |
| openresty/ | acd832254d9c | curl | 8.22.0-r0 | 1 |
| penpotapp/ | 94fa2864d8fc | curl | 8.22.0-r0 | 1 |
| redocly/ | 2e26bb660574 | curl | 8.22.0-r0 | 1 |
| reportportal/ | 06cdf299b397 | curl | 8.22.0-r0 | 1 |
| robiningelbrecht/ | 40842cdfd616 | curl | 8.22.0-r0 | 1 |
| signalen/ | 1ab79cb7fe21 | curl | 8.22.0-r0 | 1 |
| supabase/ | f371b5f3f2ac | curl | 8.22.0-r0 | 1 |
| temporalio/ | f14912b699cf | curl | 8.22.0-r0 | 1 |
| twentycrm/ | e7d9948bf284 | curl | 8.22.0-r0 | 1 |
| udhos/ | 196ef68af380 | curl | 8.22.0-r0 | 1 |
| udhos/ | e588db500edf | curl | 8.22.0-r0 | 1 |
| udhos/ | cf7979da82e1 | curl | 8.22.0-r0 | 1 |
| wsjbr/ | 5e594f5f09f6 | curl | 8.21.0-r0 | 1 |
| gcr.io/ | 6d35276c2562 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 7930061993f7 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | cc9a028d9c43 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 2d4d776f6362 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 16759fa523f8 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 0767b242240d | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 896e4926e0d7 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | fce5b6fd161c | curl | 8.21.0-r0 | 1 |
| ghcr.io/ | bc2f49e9bb3e | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 269d0e55ea97 | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 84edfe8a67a8 | curl | 8.21.0-r0 | 1 |
| ghcr.io/ | 3aecec8bafdb | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | c26589258dec | curl | 8.22.0-r0 | 1 |
| ghcr.io/ | 372d991e5888 | curl | 8.21.0-r0 | 1 |
| ghcr.io/ | 56690a89c79a | curl | 8.21.0-r0 | 1 |
| ghcr.io/ | 80cb090162b4 | curl | 8.21.0-r0 | 1 |
| ghcr.io/ | b7da6e9defbe | curl | 8.21.0-r0 | 1 |
| ghcr.io/ | 24f2d793cb7f | curl | 8.21.0-r0 | 1 |
| ghcr.io/ | a566e7d364b9 | curl | 8.21.0-r0 | 1 |