StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
helm-watchdog-pod-deletehelm-watchdog-pod-delete0.3.01 of 1See more

helm-watchdog-pod-delete helm-watchdog-pod-delete 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,152
hpe-cosi-driverhpe-storageVerified publisher2.0.01 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,666
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,563
coreinstill-aiOfficialVerified publisher0.1.754 of 15See more

core instill-ai 0.1.75

4 of the 15 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
instill/mgmt-backend:d0933d4ebe12f77a3f9
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
instill/model-backend:611f0f2e980125e5ba5
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
temporalio/admin-tools:1.28cfde8170c92f
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

30,920
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

4,357
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

4,634
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,375
kanister-operatorkanister0.118.01 of 1See more

kanister-operator kanister 0.118.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,163
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,285
radondb-mysqlkubesphere-testVerified publisher1.0.11 of 3See more

radondb-mysql kubesphere-test 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,381
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,630
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,004
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,940
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

17,755
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

3,794
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

5,066
gateway-apinicklasfrahm-gateway-apiVerified publisher0.2.01 of 1See more

gateway-api nicklasfrahm-gateway-api 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.33.32c59a3f0726c
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,257
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

5,224
oesopsmxVerified publisher4.0.328 of 25See more

oes opsmx 4.0.32

8 of the 25 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
nghttp2@1.65.0-r0
1.68.1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

107,899
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.2

Open the chart page →

2,994
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,079
repoflowrepoflow-helm-public0.9.12 of 8See more

repoflow repoflow-helm-public 0.9.1

2 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
library/elasticsearch:8.15.0310b9fc03b06
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

13,615
rocketmq-clusterrocketmq12.6.02 of 2See more

rocketmq-cluster rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

6,385
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

24,549
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,466
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

860
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

5,889
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,814
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

15,525
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,064
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

28,579
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

10,355
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

18,149
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

4,428
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,085
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

4,713
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

4,016
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,836
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

13,683
agentareaagentareaVerified publisher0.0.182 of 16See more

agentarea agentarea 0.0.18

2 of the 16 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
temporalio/auto-setup:1.29.15b3502a3b685
nghttp2@1.65.0-r0
1.68.1
temporalio/ui:2.39.0b768f87f18b5
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

14,960
icat-k8salba-helm-chartsVerified publisher1.1.01 of 4See more

icat-k8s alba-helm-charts 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
curlimages/curl:8.18.0d94d07ba9e7d
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,744
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

11,936
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

12,061
upcloud-csiankra-chartsVerified publisher0.4.01 of 8See more

upcloud-csi ankra-charts 0.4.0

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

14,920
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

7,790
scannerappscodeVerified publisher2026.1.151 of 3See more

scanner appscode 2026.1.15

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

5,301
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,231
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

17,946
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

13,199
aramid-indexerbiatec-repoVerified publisher3.9.01 of 5See more

aramid-indexer biatec-repo 3.9.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

13,513

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/aerokube/keygen:1.0.1578934444f04
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
nghttp2@1.68.0-r0
1.68.1
1
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.