StackRadar

CVE-2026-9547

High

Advisory

Published 24 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,250
of 17,790 indexed, latest versions
Container images
1,112
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,250 of 17,790 indexed charts deploy, on 1,112 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4+48 more7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2+e15, 8.14.1-2ubuntu1.4+1 more902
curlapk8.12.1-r0, 8.17.0-r1, 8.18.0-r0, 8.19.0-r0+2 more8.21.0-r0, 8.22.0-r0210
OSV records
ALPINE-CVE-2026-9547DEBIAN-CVE-2026-9547UBUNTU-CVE-2026-9547ECHO-07b2-9e60-e1ba
Also known as
USN-8487-1

Charts affected

1,250 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,112 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hyperglance/init:apacheb2f8c6d52623
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.25
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
curl@7.88.1-10+deb12u1
no fix listed
1
infiniflow/infinity:v0.7.0992c87a68612
curl@7.81.0-1ubuntu1.23
7.81.0-1ubuntu1.25
1
inseefrlab/shelly:cloudshell31f04ca7436b
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
instill/artifact-backend:b28766ac4a393e601ed
curl@8.14.1-2+deb13u2
no fix listed
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
curl@8.14.1-2+deb13u2
no fix listed
1
instill/model-backend:611f0f2e980125e5ba5
curl@8.14.1-2+deb13u2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
curl@7.88.1-10+deb12u5
no fix listed
1
inventree/inventree:1.5.4a946ec09da3e
curl@8.14.1-2+deb13u4
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
curl@7.81.0-1ubuntu1.20
7.81.0-1ubuntu1.25
1
istio/examples-helloworld-v1:latest328b237e4fb1
curl@7.88.1-10+deb12u5
no fix listed
1
istio/examples-helloworld-v2:latest0a7f02b2c7c9
curl@7.88.1-10+deb12u5
no fix listed
1
istio/install-cni:1.23.6ab34c4740f44
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
istio/install-cni:1.29.0ce27c9ce43c8
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
istio/operator:1.18.270f9d1fe5fff
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.25
1
istio/pilot:1.29.0325156535773
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
istio/pilot:1.23.69c3d6a218181
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
istio/pilot:1.16.0ac0284d75ec9
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.25
1
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.25
1
istio/pilot:1.15.2db08d6963975
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.25
1
istio/pilot:1.29.1f8b0e412ac4a
curl@8.5.0-2ubuntu10.7
8.5.0-2ubuntu10.10
1
istio/ztunnel:1.25.005f3972d80a9
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.10
1
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
no fix listed
1
jaedb/iris:latest048cfbf58d57
curl@7.88.1-10+deb12u12
no fix listed
1
jbtronics/part-db1:latest5db71f6db59d
curl@7.88.1-10+deb12u15
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
curl@8.14.1-2+deb13u2
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
curl@8.14.1-2+deb13u2
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
curl@7.88.1-10+deb12u8
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
curl@8.14.1-2+deb13u2
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
curl@7.88.1-10+deb12u6
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
curl@7.88.1-10+deb12u12
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
curl@7.88.1-10+deb12u8
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
curl@7.88.1-10+deb12u7
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
curl@7.88.1-10+deb12u5
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
curl@8.14.1-2+deb13u4
no fix listed
1
jesec/flood:4.14.3c887dad96b40
curl@8.20.0-r1
8.21.0-r0
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
curl@7.88.1-10+deb12u5
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
curl@7.88.1-10+deb12u14
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
curl@7.88.1-10+deb12u15
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
curl@8.5.0-2ubuntu10.9
8.5.0-2ubuntu10.10
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
curl@8.20.0-r0
8.22.0-r0
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
curl@8.5.0-2ubuntu10.4
8.5.0-2ubuntu10.10
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
curl@7.81.0-1ubuntu1.15
7.81.0-1ubuntu1.25
1
kayrosuno/kping:latestf3bd44b29b0d
curl@8.5.0-2ubuntu10.7
8.5.0-2ubuntu10.10
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
curl@8.17.0-r1
8.22.0-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
curl@8.17.0-r1
8.22.0-r0
1
kimai/kimai2:2.67.03084f1e5ecdc
curl@7.88.1-10+deb12u15
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.