StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,447
of 17,792 indexed, latest versions
Container images
1,495
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,447 of 17,792 indexed charts deploy, on 1,495 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more931
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more321
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1243
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,447 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,495 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
nghttp2@1.68.0-r0
1.68.1
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-6.el8_10.2
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
nghttp2@1.68.0-r0
1.68.1
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
nghttp2@1.65.0-r0
1.68.1
1
ghcr.io/blessingnator/keycloak-mcn-frontend:2.0.1ddd462dbde39
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
nghttp2@1.65.0-r0
1.68.1
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
nghttp2@1.65.0-r0
1.68.1
1
ghcr.io/colanode/web:latestbcad696f03ee
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
nghttp2@1.65.0-r0
1.68.1
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/dakera-ai/dakera-dashboard:0.3.292e059589f7f7
nghttp2@1.68.0-r0
1.68.1
1
ghcr.io/dani-garcia/vaultwarden:1.33.2-alpine63cce7624f65
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/dask/dask:2024.1.0080150de7d86
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.