StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,790 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,790 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1246
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,571

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
istio/examples-helloworld-v2:latest0a7f02b2c7c9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
istio/install-cni:1.10.32232f365aed6
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/install-cni:1.23.6ab34c4740f44
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/install-cni:1.29.0ce27c9ce43c8
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/operator:1.10.3655eefa11c84
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/operator:1.12.06cfce8a071b9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
istio/operator:1.18.270f9d1fe5fff
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.10.0294ca55bd1cc
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/pilot:1.29.0325156535773
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/pilot:1.23.69c3d6a218181
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.17.1ce9d87606701
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.15.2db08d6963975
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.10.3e7e110a421c2
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/pilot:1.29.1f8b0e412ac4a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/proxyv2:1.9.687a9db561d2e
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/proxyv2:1.10.088c6c693e67a
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/proxyv2:1.14.1df69c1a7af7c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
istio/ztunnel:1.25.005f3972d80a9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
ixsystems/truecommand:3.2.019c218455cd2
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jacobalberty/unifi:v7.1.664a3616625dda
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
jaedb/iris:latest048cfbf58d57
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jakowenko/double-take:1.6.0b858bac9e32a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
nghttp2@1.64.0-r0
1.68.1
1
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
nghttp2@1.64.0-r0
1.68.1
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
nghttp2@1.65.0-r0
1.68.1
1
jedi132000/nextapp:latestdc2a81e92f23
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jellyfin/jellyfin:10.11.81694ff069f0c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jellyfin/jellyfin:10.11.717285f9cce63
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jellyfin/jellyfin:10.11.6333b64771663
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jellyfin/jellyfin:10.10.77ae36aab93ef
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jellyfin/jellyfin:10.10.696b09723b22f
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jhipster/jhipster-registry:latest7184525acd4d
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
1
josh5/unmanic:0.2.64d49c4816260
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
kayrosuno/kping:latestf3bd44b29b0d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
nghttp2@1.68.0-r0
1.68.1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.