StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,787 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,787 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more934
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
altinity/metrics-exporter:0.20.01a46d104406d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,422
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

45,832
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

7,126
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

5,676
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,380
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

11,459
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

24,930
stornxstornxVerified publisher1.1.12 of 9See more

stornx stornx 1.1.1

2 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
istio/pilot:1.29.1f8b0e412ac4a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

11,574
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,826
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

3,240
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

9,102
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

9,102
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

4,020
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,764
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,764
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

12,581
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

4,010
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,225
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

26,657
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

15,970
ingress-nginxwenerme4.15.11 of 2See more

ingress-nginx wenerme 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,547
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,835
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

7,696
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

8,217
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

10,090
aeneabotygdrassilOfficialVerified publisher0.2.01 of 2See more

aeneabot ygdrassil 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
elautoestopista/aeneabot:4.2.1125ba620d528
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,697
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

9,783
backendzymtraceOfficialVerified publisher26.9.11 of 6See more

backend zymtrace 26.9.1

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

10,323
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

4,554
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,713
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

3,188
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

25,443
adeptia-automate-mcpadeptia-automate-mcp1.0.02 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1

Open the chart page →

3,600
linkstackadnoctemVerified publisher0.4.01 of 1See more

linkstack adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linkstackorg/linkstack:latest1c8b05399ee4
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

2,092
bootaerokube1.0.11 of 4See more

boot aerokube 1.0.1

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/aerokube/keygen:1.0.1578934444f04
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

7,834
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

4,922
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
temporalio/auto-setup:1.27.2b44cbfeb43db
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

12,473
aktoakto0.2.02 of 7See more

akto akto 0.2.0

2 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

13,613
akto-hybrid-redactakto1.44.61See more

akto-hybrid-redact akto 1.44.6

1 container image this version deploys carries CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,276
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

3,217
akto-mini-testing-kafkaakto1.42.12 of 5See more

akto-mini-testing-kafka akto 1.42.1

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,397
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,826
akto-protectionakto0.1.02 of 4See more

akto-protection akto 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

11,285
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

4,880
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

3,442
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

6,324
lidarralexmorbo-lidarrVerified publisher0.1.21 of 1See more

lidarr alexmorbo-lidarr 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,870
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,623
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
istio/examples-helloworld-v1:latest328b237e4fb1
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
istio/examples-helloworld-v2:latest0a7f02b2c7c9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
istio/install-cni:1.10.32232f365aed6
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/install-cni:1.23.6ab34c4740f44
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/install-cni:1.29.0ce27c9ce43c8
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/operator:1.10.3655eefa11c84
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/operator:1.12.06cfce8a071b9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
istio/operator:1.18.270f9d1fe5fff
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.10.0294ca55bd1cc
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/pilot:1.29.0325156535773
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/pilot:1.23.69c3d6a218181
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.17.1ce9d87606701
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.15.2db08d6963975
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
istio/pilot:1.10.3e7e110a421c2
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/pilot:1.29.1f8b0e412ac4a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
istio/proxyv2:1.9.687a9db561d2e
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/proxyv2:1.10.088c6c693e67a
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
istio/proxyv2:1.14.1df69c1a7af7c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
istio/ztunnel:1.25.005f3972d80a9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
ixsystems/truecommand:3.2.019c218455cd2
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jacobalberty/unifi:v7.1.664a3616625dda
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
jaedb/iris:latest048cfbf58d57
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jakowenko/double-take:1.6.0b858bac9e32a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
nghttp2@1.64.0-r0
1.68.1
1
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
nghttp2@1.64.0-r0
1.68.1
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
nghttp2@1.65.0-r0
1.68.1
1
jedi132000/nextapp:latestdc2a81e92f23
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jellyfin/jellyfin:10.11.81694ff069f0c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jellyfin/jellyfin:10.11.717285f9cce63
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jellyfin/jellyfin:10.11.6333b64771663
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jellyfin/jellyfin:10.10.77ae36aab93ef
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jellyfin/jellyfin:10.10.696b09723b22f
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jhipster/jhipster-registry:latest7184525acd4d
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
1
josh5/unmanic:0.2.64d49c4816260
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
kayrosuno/kping:latestf3bd44b29b0d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.