StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

3,697
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,571

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/kubectl:1.35.2ec8f734b0a10
nghttp2@1.68.0-r0
1.68.1
2
amaraiheanacho/nginx-site:latest5c86fccf5daa
nghttp2@1.64.0-r0
1.68.1
2
apache/nifi-registry:1.26.07cdfd8deec92
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
2
apache/rocketmq:5.4.0319cd8a81ed1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
clamav/clamav:1.4.3_base629a3050df6a
nghttp2@1.68.0-r0
1.68.1
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
confluentinc/cp-zookeeper:latest7610a50b13e7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
curlimages/curl:8.15.04026b29997dc
nghttp2@1.65.0-r0
1.68.1
2
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
2
excalidraw/excalidraw:latestf7ee194addd6
nghttp2@1.64.0-r0
1.68.1
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
nghttp2@1.52.0-1
1.52.0-1+deb12u3
2
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
2
grafana/grafana:12.3.12175aaa91c96
nghttp2@1.68.0-r0
1.68.1
2
grafana/grafana:12.3.39e1e77ade304
nghttp2@1.68.0-r0
1.68.1
2
grafana/grafana:12.4.1e932bd6ed0e0
nghttp2@1.68.0-r0
1.68.1
2
helmforge/kubectl:1.35.3c3f97e954c47
nghttp2@1.65.0-r0
1.68.1
2
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
2
istio/kubectl:1.5.10dbb7726d1bf0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
1.52.0-1+deb12u3
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
kurento/kurento-media-server:latest03c0d34d0828
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
2
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
library/elasticsearch:8.19.1289729a95066a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
library/influxdb:2.7b8d940ca9376
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
library/mongo:8.0.20098862b1339f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
library/mongo:5.041108d183e97
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
2
library/mongo:4.2.358b25d51baa1
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
library/nginx:latest6e23479198b9
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
library/nginx:1.27.098f8ec75657d
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
library/nginx:1.29.49dd288848f44
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.