StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,447
of 17,787 indexed, latest versions
Container images
1,500
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,447 of 17,787 indexed charts deploy, on 1,500 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more934
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more321
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1245
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,447 by stars
ChartLatestAffected imagesRadar Score
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

8,943
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

10,994
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

9,698
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

12,581
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

14,283
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

12,958
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

12,076
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

17,702
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

27,949
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

19,503
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

15,730
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,807
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

10,379
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,768
resilio-syncgeek-cookbookVerified publisher5.4.21 of 1See more

resilio-sync geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

5,895
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,427
sdtdgeek-cookbookVerified publisher0.3.21 of 1See more

sdtd geek-cookbook 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/reitermarkus/7d2d:main39953b387b61
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

2,511
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

24,293
skypilotgeek-cookbookVerified publisher0.0.12 of 3See more

skypilot geek-cookbook 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

8,923
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

26,944
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,861
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

17,929
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

3,712
dispatchoor-uigeneral-helm-chartsVerified publisher0.1.01 of 1See more

dispatchoor-ui general-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/dispatchoor-web:latest18e30413dac2
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,338
mongogengxiankun-charts0.1.01 of 1See more

mongo gengxiankun-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

3,969
rocketmqgengxiankun-charts0.3.01 of 1See more

rocketmq gengxiankun-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/rocketmq:5.3.0434d8398f996
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

4,921
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

4,259
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.83 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

3 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
library/elasticsearch:7.17.1588c2ec10c7f2
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
library/kibana:7.17.150172f1c538e7
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1

Open the chart page →

34,754
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

16,756
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
natsio/nats-box:0.19.28031d190c7ee
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

12,056
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

12,170
gnp-stackgnp-stack0.0.51 of 14See more

gnp-stack gnp-stack 0.0.5

1 of the 14 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

7,659
jaegergpg-dev3.3.32 of 5See more

jaeger gpg-dev 3.3.3

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

19,229
kube-prometheus-stackgpg-dev84.0.01 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/grafana:13.0.10f86bada30d6
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

4,288
kubernetes-dashboardgpg-dev7.5.01 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

6,036
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

49,025
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

15,722
grafana-cloud-onboardinggrafana0.4.72 of 5See more

grafana-cloud-onboarding grafana 0.4.7

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

4,637
mimir-openshift-experimentalgrafana2.1.02 of 4See more

mimir-openshift-experimental grafana 2.1.0

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.13 of 6See more

pyroscope-monitoring grafana 0.1.1

3 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

8,188
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

4,556
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,261
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,199
routergroundcover1.12.3591See more

router groundcover 1.12.359

1 container image this version deploys carries CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,255
hatchet-hahatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-ha hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,344
hatchet-stackhatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-stack hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,344
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

9,096
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

6,708
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

24,995

Container images carrying it

1,500 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/kubectl:1.35.2ec8f734b0a10
nghttp2@1.68.0-r0
1.68.1
2
apache/nifi-registry:1.26.07cdfd8deec92
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
2
apache/rocketmq:5.4.0319cd8a81ed1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
clamav/clamav:1.4.3_base629a3050df6a
nghttp2@1.68.0-r0
1.68.1
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
confluentinc/cp-zookeeper:latest7610a50b13e7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
curlimages/curl:8.15.04026b29997dc
nghttp2@1.65.0-r0
1.68.1
2
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
2
excalidraw/excalidraw:latestf7ee194addd6
nghttp2@1.64.0-r0
1.68.1
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
nghttp2@1.52.0-1
1.52.0-1+deb12u3
2
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
2
grafana/grafana:12.3.12175aaa91c96
nghttp2@1.68.0-r0
1.68.1
2
grafana/grafana:12.3.39e1e77ade304
nghttp2@1.68.0-r0
1.68.1
2
grafana/grafana:12.4.1e932bd6ed0e0
nghttp2@1.68.0-r0
1.68.1
2
helmforge/kubectl:1.35.3c3f97e954c47
nghttp2@1.65.0-r0
1.68.1
2
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
2
istio/kubectl:1.5.10dbb7726d1bf0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
1.52.0-1+deb12u3
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
kurento/kurento-media-server:latest03c0d34d0828
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
2
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
library/elasticsearch:8.19.1289729a95066a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
library/influxdb:2.7b8d940ca9376
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
library/mongo:8.0.20098862b1339f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
library/mongo:5.041108d183e97
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
2
library/mongo:4.2.358b25d51baa1
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
library/nginx:latest6e23479198b9
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
library/nginx:1.27.098f8ec75657d
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
library/nginx:1.29.49dd288848f44
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
library/phpmyadmin:5.2.16e75aa8f767c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.