StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2api:3.86f56d239d280
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2auth:3.833ecfda16608
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2notifier:3.8f190a6212195
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2rulesengine:3.8259503496ff9
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2scheduler:3.8b1de2055c362
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2stream:3.81c8904a3bf67
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2web:3.809989a26c8b7
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.02 of 14See more

supabase tokens-studio 1.0.0

2 of the 14 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
supabase/realtime:v2.33.8d207e6e23ad3
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
supabase/studio:20241021-9f9b08326d8070c55e9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

23,263
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

8,530
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,810
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,110
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

7,896
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

4,412
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,453
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,154
umamichristianhuthVerified publisher7.13.01 of 2See more

umami christianhuth 7.13.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,368
devtron-operatordevtron0.23.31 of 11See more

devtron-operator devtron 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

5,396
envoy-gatewayhelmforgeVerified publisher2.1.01 of 3See more

envoy-gateway helmforge 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
helmforge/kubectl:1.35.3c3f97e954c47
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

2,391
ilumilumOfficialVerified publisher6.7.32 of 19See more

ilum ilum 6.7.3

2 of the 19 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
nghttp2@1.65.0-r0
1.68.1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

23,289
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

3,434
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,031
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

5,665
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

4,344
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

30,481
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

14,276
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,831
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,333
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

6,386
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,321
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

5,669
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

30,811
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

6,484
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

9,868
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,163
codercoderOfficialVerified publisher1.44.62 of 2See more

coder coder 1.44.6

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
coderenvs/timescale:1.44.676fd37fe6830
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

6,847
emqx-operatoremqx-operator2.3.21 of 2See more

emqx-operator emqx-operator 2.3.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

4,532
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

2,811
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

4,951
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

2,913
mercuremercureOfficialVerified publisher0.24.01 of 1See more

mercure mercure 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dunglas/mercure:v0.24.080fcb704a741
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,409
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

8,685
rekorsigstoreVerified publisher1.8.51 of 9See more

rekor sigstore 1.8.5

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
curlimages/curldigest-pinned935d9100e9ba
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

5,416
thehivestrangebee-helmOfficialVerified publisher1.0.63 of 7See more

thehive strangebee-helm 1.0.6

3 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
curlimages/curl:8.17.0935d9100e9ba
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

16,161
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

14,266
agonesagones1.60.01 of 5See more

agones agones 1.60.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.49ccd82364762
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,122
cloudflaredartur9010Verified publisher1.0.91 of 3See more

cloudflared artur9010 1.0.9

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,990
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

17,346
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

53,012
seafiledatamateVerified publisher0.6.02 of 6See more

seafile datamate 0.6.0

2 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
datamate/seafile-professional:11.0.202dd66b722464
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

27,358
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,578
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

12,270
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,396
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
apache/hertzbeat-collector:1.8.0a2bab1be574c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

14,109

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/hpestorage/filex-csi-init:2.6.42d867eefb233
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/jupyterhub/configurable-http-proxy:5.1.0eb10d5bf045c
nghttp2@1.64.0-r0
1.68.1
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.