StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,790 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,790 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1246
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,571

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
kinseii/wazuh-agent:4.14.17160eb143728
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
knspar/phronetis-operator:0.1.60c4f0543ee58
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
nghttp2@1.68.0-r0
1.68.1
1
kong/httpbin:latesta6ac46531193
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
krontechnology/aapm-service:1.1.39dd602db8baa
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
kubeflow/model-registry:v0.2.95783f6db428f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
kuberay/operator:v1.0.04e6ac8a3a2c4
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.2
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
nghttp2@1.68.0-r0
1.68.1
1
kusionstack/kusion:v0.14.0126c8f0b0976
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
kuzwolka/aws9:main1ad759b961b1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
kuzwolka/aws9:news3e8880fbbb96
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
kuzwolka/aws9:blog4a7707410bf1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
kuzwolka/aws9:shop84a9d9766345
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
laly9999/node-app:1dd0e503913e1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
langflowai/langflow-frontend:latest54f67f1961fe
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
langgenius/dify-api:1.0.0066035f93856
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
langgenius/dify-api:0.6.11fca918260dd6
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
layer5/meshery:stable-latest78a8be21bef3
nghttp2@1.64.0-r0
1.68.1
1
lib42/jackett:latesta55596cda383
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
library/caddy:2.11.2-alpine834468128c76
nghttp2@1.68.0-r0
1.68.1
1
library/cassandra:3.11.10b095ff3248c6
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
library/couchdb:3.4.22817ad50b5c5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
library/docker:28.5.2-dind2a232a42256f
nghttp2@1.65.0-r0
1.68.1
1
library/docker:27-cli851f91d24121
nghttp2@1.64.0-r0
1.68.1
1
library/docker:27-dindaa3df78ecf32
nghttp2@1.64.0-r0
1.68.1
1
library/elasticsearch:8.17.32cc40b15dff8
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
library/elasticsearch:8.15.0310b9fc03b06
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
library/elasticsearch:7.17.0332c6d416808
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
library/elasticsearch:7.17.1588c2ec10c7f2
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
1
library/elasticsearch:7.17.8fdc73b3249c1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
library/flink:1.14.6-scala_2.122461f02672b3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
library/httpd:2.4.631ae8051591a5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
library/influxdb:1.12.3-meta8812029260b5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
library/influxdb:1.12.3-datab0f9fc41ed79
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
library/kibana:7.17.150172f1c538e7
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
1
library/kibana:8.18.004c0fc150f3a
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
library/kibana:7.17.8c5781ba340ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
library/kibana:7.17.3e2e2031c15be
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
library/logstash:7.17.817a4f64e9cf5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
library/logstash:9.1.233eae14f0867
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
library/matomo:5.1.2-apache2415789e1602
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
library/mongo:7.0.140032d2ca20db
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
library/mongo:4.4.1305678ae4e5e1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.