StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,790 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,790 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1246
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

3,062
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,577
radar-upload-connect-frontendradar-baseVerified publisher0.8.11 of 1See more

radar-upload-connect-frontend radar-base 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

937
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

2,782
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,968
pagesranjinigogga1.0.02 of 3See more

pages ranjinigogga 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,242
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
oxfordsemantic/rdfox-init:5.6baf570ff968d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,884
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

15,570
sqpreadyset-sqp-nightly0.1.0-nightly.202604302 of 3See more

sqp readyset-sqp-nightly 0.1.0-nightly.20260430

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
readysettech/sqp:latest588f3507280e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
readysettech/sqp-duckdb:latest67a83203ce60
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

3,524
pagesrebecca-pages1.0.02 of 3See more

pages rebecca-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,242
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,382
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

15,299
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

15,299
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

11,446
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

4,245
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.2

Open the chart page →

16,388
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

29,564
redis-enforce-expireredis-enforce-expire1.0.01 of 1See more

redis-enforce-expire redis-enforce-expire 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
udhos/redis-enforce-expire:1.0.0615b6a7d742e
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,303
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

7,459
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,955
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

4,624
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
istio/examples-helloworld-v2:latest0a7f02b2c7c9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

9,452
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

3,882
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

15,681
wallosrm3lVerified publisher0.1.01 of 1See more

wallos rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,529
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,242
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

5,430
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

9,299
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,763
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

9,685
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

13,011
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

68,695
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

4,972
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

33,180
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,959
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rommapp/romm:5.2.03512f2ca4557
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,420
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,242
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

6,954
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

4,615
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

4,615
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

10,638
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

4,549
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

6,303
trmnl-serverrubxkubeVerified publisher0.1.01 of 2See more

trmnl-server rubxkube 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

2,778
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,102
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

5,852
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

8,733
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

9,631
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

7,403

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/dakera-ai/dakera-dashboard:0.3.292e059589f7f7
nghttp2@1.68.0-r0
1.68.1
1
ghcr.io/dani-garcia/vaultwarden:1.33.2-alpine63cce7624f65
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/dask/dask:2024.1.0080150de7d86
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
ghcr.io/data-fair/notify:3c739b74dabb0
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
nghttp2@1.64.0-r0
1.68.1
1
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
nghttp2@1.68.0-r0
1.68.1
1
ghcr.io/ethpandaops/dispatchoor-web:latest18e30413dac2
nghttp2@1.68.0-r0
1.68.1
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.