StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,460
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

1,724
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

6,354
keycloak-operatorkeycloak-operatorVerified publisher0.0.41 of 1See more

keycloak-operator keycloak-operator 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

4,662
percona-xtradb-clusterkfirfer1.5.101 of 3See more

percona-xtradb-cluster kfirfer 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

4,956
kubeflowkubeflow1.6.23 of 45See more

kubeflow kubeflow 1.6.2

3 of the 45 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
istio/proxyv2:1.14.1df69c1a7af7c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
library/python:3.7eedf63967cdb
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

97,040
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

10,569
venti-stackkuossOfficialVerified publisher0.5.02 of 9See more

venti-stack kuoss 0.5.0

2 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kuoss/lethe:v0.3.3ebdf55fd5705
nghttp2@1.65.0-r0
1.68.1
ghcr.io/kuoss/venti:v0.3.38ee3e70d77f1
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

3,810
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

2,654
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

5,833
radarrloeken-at-homeVerified publisher5.27.0-nightly1 of 1See more

radarr loeken-at-home 5.27.0-nightly

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
loeken/radarr:5.27.0-nightlya24409d3846d
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

586
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,968
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gradiant/open5gs-dbctl:0.10.3332031245fce
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

9,300
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

8,767
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1

Open the chart page →

10,536
fulciosigstoreVerified publisher2.11.11 of 6See more

fulcio sigstore 2.11.1

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

3,491
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

19,363
unboundunbound-helmchartVerified publisher0.2.21 of 1See more

unbound unbound-helmchart 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,495
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,996
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

9,753
eshoponabpabp-charts1.0.01 of 15See more

eshoponabp abp-charts 1.0.0

1 of the 15 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:4.2699d652ed674
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

19,805
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

8,251
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,133
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
nghttp2@1.33.0-3.el8_2.2
0:1.33.0-6.el8_10.2

Open the chart page →

9,052
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

8,007
certscertsVerified publisher2.1.31 of 1See more

certs certs 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
mathnao/certs:2.1.3b900e6b64684
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

695
collabora-codechrisingenhaag2.6.01 of 1See more

collabora-code chrisingenhaag 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
collabora/code:23.05.10.1.105299b452f7f
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

4,184
coder-observabilitycoder-observabilityVerified publisher0.7.33 of 21See more

coder-observability coder-observability 0.7.3

3 of the 21 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/grafana:10.4.19a9043254ba16
nghttp2@1.64.0-r0
1.68.1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

24,698
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1

Open the chart page →

7,476
convertigoconvertigoOfficialVerified publisher8.4.32 of 5See more

convertigo convertigo 8.4.3

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
library/couchdb:3.4.22817ad50b5c5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

17,475
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

3,081
cosmocosmo-platformOfficialVerified publisher0.20.02 of 10See more

cosmo cosmo-platform 0.20.0

2 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

27,984
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

9,348
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

4,194
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
curlimages/curl:8.18.0d94d07ba9e7d
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,872
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

2,012
edgelessdbedgelesssysVerified publisher0.3.21 of 1See more

edgelessdb edgelesssys 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

4,868
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.2

Open the chart page →

14,545
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.2

Open the chart page →

13,874
zabbix-agentfermosit0.0.51 of 1See more

zabbix-agent fermosit 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

2,408
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

5,302
healthchecksgabe565Verified publisher0.17.01 of 1See more

healthchecks gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

2,285
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

22,812
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

14,001
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

9,666
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

10,202
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

10,676
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

11,873
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.21 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,245

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/aerokube/keygen:1.0.1578934444f04
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
nghttp2@1.68.0-r0
1.68.1
1
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.