StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,790 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,790 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1246
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

7,938
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,986
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,460
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

12,628
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2fac502149c40
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
nghttp2@1.33.0-1.el8
0:1.33.0-6.el8_10.2

Open the chart page →

12,161
monitoring-stackict-platformVerified publisher0.4.02 of 13See more

monitoring-stack ict-platform 0.4.0

2 of the 13 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

9,629
ingress-nginxifmethod-helm-charts4.12.11 of 2See more

ingress-nginx ifmethod-helm-charts 4.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,477
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

3,210
eoloserverihuertas2021-vmartinp2021-helm0.1.03 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

27,822
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

9,038
ikigaiikigai-chartVerified publisher0.0.94 of 58See more

ikigai ikigai-chart 0.0.9

4 of the 58 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
kuberay/operator:v1.0.04e6ac8a3a2c4
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.2
library/zookeeper:3.8-temurin55d1e5b2e601
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

37,874
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/jupyterhub/configurable-http-proxy:5.1.0eb10d5bf045c
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,843
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

11,885
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

16,230
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,363
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
library/influxdb:1.12.3-datab0f9fc41ed79
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,980
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

10,554
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,157
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,471
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

18,155
kesintelVerified publisher0.8.31 of 1See more

kes intel 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
minio/kes:v0.22.255f3aef5803e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

3,577
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

5,999
intelowlintelowl-helm6.6.1-01-06-20262 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
intelowlproject/intelowl_nginx:v6.6.12f01e79b8064
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

17,966
interbtc-parachaininterlay0.4.131 of 1See more

interbtc-parachain interlay 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

3,197
polkabtc-parachaininterlay0.2.412 of 4See more

polkabtc-parachain interlay 0.2.41

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
byrnedo/alpine-curl:latest7f0599d553e2
nghttp2@1.65.0-r0
1.68.1
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

3,940
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

5,579
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

5,579
ztunnelistio-ztunnelVerified publisher1.25.01 of 1See more

ztunnel istio-ztunnel 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/ztunnel:1.25.005f3972d80a9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,502
daveit-at-mOfficialVerified publisher0.2.152 of 11See more

dave it-at-m 0.2.15

2 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

15,277
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,975
wjh-rechnerit-at-mOfficialVerified publisher1.0.41 of 1See more

wjh-rechner it-at-m 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_7.1

Open the chart page →

3,501
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

45,472
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,864
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

2,091
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,103
manyfoldjeffrescVerified publisher1.0.31 of 1See more

manyfold jeffresc 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,961
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

4,511
jellyfinjellyfin--jellyfin-helm3.0.01 of 1See more

jellyfin jellyfin--jellyfin-helm 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.717285f9cce63
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

3,022
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2

Open the chart page →

9,854
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,858
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,259
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

7,838
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

6,655
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

6,637
image-storage-servicejtektVerified publisher0.4.33 of 4See more

image-storage-service jtekt 0.4.3

3 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

22,728
shinsei-managerjtektVerified publisher0.2.07 of 8See more

shinsei-manager jtekt 0.2.0

7 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
moreillon/group-manager:latest3caa8f710ee0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
moreillon/group-manager-front:latest5f0a38498271
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u3
moreillon/user-manager-front:v5.0.3b067dbbbb6af
nghttp2@1.52.0-1
1.52.0-1+deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

63,822
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

16,680
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,967
jupyter-hub-customizationsjupyter-jscVerified publisher0.27.171 of 4See more

jupyter-hub-customizations jupyter-jsc 0.27.17

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/nginx:1.291881968aff6f
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

3,412
jupyter-nginxjupyter-jscVerified publisher0.1.31 of 1See more

jupyter-nginx jupyter-jsc 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

3,531

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/aerokube/keygen:1.0.1578934444f04
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
nghttp2@1.68.0-r0
1.68.1
1
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.