StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

4,007
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,215
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

15,077
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

22,146
picoclawpicoclawVerified publisher0.1.261 of 1See more

picoclaw picoclaw 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/mattn/picoclaw:latest517556c8b144
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,557
pagespighosh-pages1.0.02 of 3See more

pages pighosh-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,233
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

7,149
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

11,373
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

6,695
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

6,641
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

4,938
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

11,017
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

7,616
planectlplanectlVerified publisher0.7.02 of 10See more

planectl planectl 0.7.0

2 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/node:208f693eaa7e0a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
quay.io/argoproj/argocd:v2.14.115fc69e31c755
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

25,626
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2

Open the chart page →

11,153
k8s-oidc-discovery-providerpnnl-miscscripts0.1.22 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
nghttp2@1.65.0-r0
1.68.1
library/nginx:1.29.49dd288848f44
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

4,273
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,754
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

11,680
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

9,212
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

6,575
quickwitportefaix-hub0.1.11 of 1See more

quickwit portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.1d29332bdadcc
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

3,185
keydbpozetron0.5.31 of 1See more

keydb pozetron 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
pozetroninc/keydb:v6.0.1653ae64f29da8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

7,014
Practica_4_helmpr04helm0.1.03 of 7See more

Practica_4_helm pr04helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

27,649
practica-helmpractica-helm0.1.02 of 7See more

practica-helm practica-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:4.4-bionic3d0e6df9fd5b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
slagattollas/weatherservice-practica:latest68e7f56393fc
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

28,495
pagesprasanthi1.0.02 of 3See more

pages prasanthi 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,233
prefect-agentprefectVerified publisher2024.8.301638221 of 1See more

prefect-agent prefect 2024.8.30163822

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

4,996
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,316
trinopresto-loadbalancer0.2.101 of 2See more

trino presto-loadbalancer 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
trinodb/trino:4796af989b0846d
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1

Open the chart page →

2,264
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

6,932
prismeai-appsprismeai0.7.11 of 4See more

prismeai-apps prismeai 0.7.1

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,752
prismeai-coreprismeai1.12.11 of 7See more

prismeai-core prismeai 1.12.1

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,271
prompt-dbprompt-dbVerified publisher1.0.71 of 3See more

prompt-db prompt-db 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

3,312
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,667
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

12,652
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

11,400
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

11,400
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
nghttp2@1.39.2-lp151.3.3.1
1.68.1-1.1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
nghttp2@1.39.2-lp151.3.3.1
1.68.1-1.1

Open the chart page →

11,942
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,691
rabbitpingrabbitping1.3.01 of 1See more

rabbitping rabbitping 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
udhos/rabbitping:1.3.0474c467bbf42
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

889
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

4,117
rada-platformrada-platform0.1.03 of 7See more

rada-platform rada-platform 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
trinodb/trino:45038c6f24ab1a4
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1

Open the chart page →

20,812
app-configradar-baseVerified publisher1.7.21 of 1See more

app-config radar-base 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,075
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,457
data-dashboard-backendradar-baseVerified publisher0.6.21 of 1See more

data-dashboard-backend radar-base 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,058
kubecostradar-baseVerified publisher1.0.02 of 7See more

kubecost radar-base 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

9,389
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

5,269
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,322
radar-grafanaradar-baseVerified publisher0.1.41 of 2See more

radar-grafana radar-base 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/grafana:11.6.062d2b9d20a19
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,667
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

2,178
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,893

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
frankescobar/allure-docker-service:2.21.08a4d7e9308de
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
galaxy/cloudman-server:lateste5c265fe9fcd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
nghttp2@1.65.0-r0
1.68.1
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
nghttp2@1.65.0-r0
1.68.1
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
gethue/hue:4.11.011b649636e68
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
gethue/hue:4.10.05702b2c37ff9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
gethue/hue:latest7d5c1b9f8a79
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
getmeili/meilisearch:v1.30.0f3ecbc8c5bfb
nghttp2@1.65.0-r0
1.68.1
1
getsentry/relay:24.10.0ba7bf9163219
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
gitea/act_runner:0.3.1c2a169c5e998
nghttp2@1.68.0-r0
1.68.1
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
gotenberg/gotenberg:8.30206a6c708fc6
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
gotson/komga:0.99.49b15ea6bfc30
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
gradiant/open5gs-dbctl:0.10.3332031245fce
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
grafana/grafana:13.0.10f86bada30d6
nghttp2@1.68.0-r0
1.68.1
1
grafana/grafana:12.2.22ebef928d7e5
nghttp2@1.65.0-r0
1.68.1
1
grafana/grafana:12.2.135c41e0fd029
nghttp2@1.65.0-r0
1.68.1
1
grafana/grafana:11.6.062d2b9d20a19
nghttp2@1.64.0-r0
1.68.1
1
grafana/grafana:12.3.070d9599b186c
nghttp2@1.65.0-r0
1.68.1
1
grafana/grafana:12.2.074144189b384
nghttp2@1.65.0-r0
1.68.1
1
grafana/grafana:12.1.1a1701c218024
nghttp2@1.65.0-r0
1.68.1
1
grafana/grafana:10.4.19a9043254ba16
nghttp2@1.64.0-r0
1.68.1
1
grafana/grafana:12.0.2b5b59bfc7561
nghttp2@1.64.0-r0
1.68.1
1
grafana/grafana:12.3.2ba93c9d192e5
nghttp2@1.68.0-r0
1.68.1
1
grafana/oncall:v1.16.5499851658393
nghttp2@1.64.0-r0
1.68.1
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
graylog/graylog:6.1.1019de1aff48c2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
gridgain/gridgain9:9.1.1895018390077b
nghttp2@1.68.0-r0
1.68.1
1
grpl/grapple-cli:0.2.127c00aafee6629
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
1
guacamole/guacamole:1.5.50f62f6d17ab3
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
gulacedia/web-dvwa-new:v367b467d961ca
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
gurolakman/oam:4.0.0ed8fd2062548
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
gurolakman/ussigw-core:1.0.48739565c3ea2
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.