StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,447
of 17,787 indexed, latest versions
Container images
1,500
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,447 of 17,787 indexed charts deploy, on 1,500 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more934
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more321
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1245
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,447 by stars
ChartLatestAffected imagesRadar Score
ingress-nginxingress-nginx4.15.11 of 2See more

ingress-nginx ingress-nginx 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,547
giteagiteaOfficialVerified publisher12.7.01 of 4See more

gitea gitea 12.7.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,811
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

6,556
artifact-hubartifact-hubVerified publisher1.23.01 of 7See more

artifact-hub artifact-hub 1.23.0

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

10,755
jupyterhubjupyterhubOfficialVerified publisher4.4.21 of 7See more

jupyterhub jupyterhub 4.4.2

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

7,894
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

11,367
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,713
trinotrino1.42.21 of 1See more

trino trino 1.42.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
trinodb/trino:4801565e8cac299
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1

Open the chart page →

1,309
zabbixzabbix-communityVerified publisher7.1.04 of 5See more

zabbix zabbix-community 7.1.0

4 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

13,664
graylogkong-zVerified publisher3.0.321 of 5See more

graylog kong-z 3.0.32

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

2,699
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

5,366
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

5,552
rocketchatrocketchat-server7.0.21 of 12See more

rocketchat rocketchat-server 7.0.2

1 of the 12 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
natsio/nats-box:0.19.28031d190c7ee
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

12,279
clamavwiremindVerified publisher3.7.31 of 1See more

clamav wiremind 3.7.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
clamav/clamav:1.4.3_base629a3050df6a
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,060
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

9,145
milvusmilvus4.0.313 of 5See more

milvus milvus 4.0.31

3 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
milvusdb/milvus:v2.2.13a3a55e1c1497
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

32,259
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,622
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

1,127
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

2,172
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

2,705
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

4,802
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.20e951a1d07bb
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

4,983
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

19,391
vaultwardengabe565Verified publisher0.16.11 of 1See more

vaultwarden gabe565 0.16.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.33.2-alpine63cce7624f65
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

451
pulsarapache4.7.03 of 10See more

pulsar apache 4.7.0

3 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
nghttp2@1.68.0-r0
1.68.1
curlimages/curl:8.18.0d94d07ba9e7d
nghttp2@1.68.0-r0
1.68.1
grafana/grafana:12.4.1e932bd6ed0e0
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

9,864
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

3,606
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

6,927
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

925
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

1,869
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

16,251
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

19,926
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

11,384
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

33,725
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

6,543
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,364
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

5,240
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,987
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

12,746
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,993
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

3,382
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

15,592
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,880
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,854
glasskube-operatorglasskubeOfficialVerified publisher0.12.22 of 3See more

glasskube-operator glasskube 0.12.2

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

11,933
milvusmilvus-helm5.0.281See more

milvus milvus-helm 5.0.28

1 container image this version deploys carries CVE-2026-27135.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

mssqlmssqlVerified publisher1.10.31 of 1See more

mssql mssql 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1

Open the chart page →

642
rocketmqrocketmq12.6.02 of 2See more

rocketmq rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

6,328
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

18,509
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

6,675
codefreshcodefresh-onpremOfficialVerified publisher2.12.132 of 42See more

codefresh codefresh-onprem 2.12.13

2 of the 42 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
bitnamilegacy/rabbitmq:4.1.39e635efba431
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

14,956

Container images carrying it

1,500 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
praravind1801/helmimages:3.0.0f29d637b9ce1
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
project2team4/react:latest3ff031a08887
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
1
pschichtel/mindustry-server:v145.1b543e9c2d371
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
psorab/elibrary:latest53b68896c4ce
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
quickwit/quickwit:v0.8.1d29332bdadcc
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
qumine/minecraft-server:v0.1.15c0b650d51132
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
rabeh/apibootspring:1.0941007b6946e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
nghttp2@1.65.0-r0
1.68.1
1
razorbladex401/dayz:latest6a4d79248e7d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
razzy10/product-service:latest702e411956db
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
readysettech/sqp:latest588f3507280e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
readysettech/sqp-duckdb:latest67a83203ce60
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
redash/redash:25.8.000d813437db5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
redash/redash:26.3.0c5c9148f5c38
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
resurfaceio/resurface:3.7.84d5cda2f64109
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
rezachalak/bzen-mongo:1.0.034f694325191
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
rm3l/dev-feed-api:latest9a7f732245a3
nghttp2@1.43.0-5.el9_2.1
0:1.43.0-6.el9_7.1
1
rm3l/mac-oui:1.8.03a5e1f95c132
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
robotshop/rs-mongodb:latest119b545823cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
rocketchat/freeswitch:stablecfba5c20a5cc
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
rommapp/romm:5.2.03512f2ca4557
nghttp2@1.68.0-r0
1.68.1
1
rommapp/romm:4.4.1b909e95d1aab
nghttp2@1.65.0-r0
1.68.1
1
rtuszik/photon-docker:2.4.021549c60f9e6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
rustfs/rustfs:1.0.0-alpha.947d49faa88c04
nghttp2@1.68.0-r0
1.68.1
1
rustfs/rustfs:1.0.0-alpha.738e467b32af3f
nghttp2@1.65.0-r0
1.68.1
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
saidsef/scapy-containerised:v2025.02f17f7c435891
nghttp2@1.64.0-r0
1.68.1
1
santisbon/speedtest:latest8ee3a1697227
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
sarwansharma/minio:v359d1da9385d1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
scrapinghub/splash:3.4.1a5f89bc84606
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
seafileltd/seafile-mc:9.0.106693911bcc40
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
seafileltd/seafile-mc:10.0.170628f29c663
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
1
seafileltd/seafile-mc:9.0.97ac833196f60
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.