StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,448
of 17,781 indexed, latest versions
Container images
1,501
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,448 of 17,781 indexed charts deploy, on 1,501 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more321
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1245
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,448 by stars
ChartLatestAffected imagesRadar Score
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

13,025
tdarrgeek-cookbookVerified publisher4.6.22 of 2See more

tdarr geek-cookbook 4.6.2

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
haveagitgat/tdarr_node:2.00.101e3f9328327d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

31,000
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest20fde516ce31
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

4,879
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,660
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.4.4c0224a1adf7a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

15,562
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

10,072
harp-proxyharp0.8.11 of 1See more

harp-proxy harp 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
makersquad/harp-proxy:0.8.1a40dd258c527
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

6,374
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

4,711
app-blueprinthelm-app-blueprintVerified publisher0.2.11 of 1See more

app-blueprint helm-app-blueprint 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

840
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

8,716
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,977
helmuphelmupVerified publisher0.1.02 of 3See more

helmup helmup 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

16,514
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.42 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

2 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
quay.io/hpestorage/filex-csi-init:2.6.42d867eefb233
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

6,095
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

4,300
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

12,397
cyberchefhv-helm-repo0.3.31 of 1See more

cyberchef hv-helm-repo 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/gchq/cyberchef:11.0.045082a0ac41d
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,109
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,470
ilum-coreilumOfficialVerified publisher6.7.31 of 5See more

ilum-core ilum 6.7.3

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

3,556
odooimioVerified publisher3.0.21 of 3See more

odoo imio 3.0.2

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/nginx:1.29.8-alpine5616878291a2
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,068
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

15,712
elasticinseefrlab2.2.02 of 2See more

elastic inseefrlab 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
library/kibana:7.17.3e2e2031c15be
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

17,284
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

11,764
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

10,400
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

10,475
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

10,421
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

10,421
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

10,701
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

9,318
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

7,387
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.321 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

1 of the 17 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

15,418
readarrk8s-home-lab-repo7.2.11 of 1See more

readarr k8s-home-lab-repo 7.2.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/home-operations/readarr:0.4.188f7551205fbd
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,099
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
kafkakraft/kafka-controller:3.7.0f261ad288fce
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
kafkakraft/kafkakraft:3.7.02e4b593b878b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

14,130
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,508
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,789
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,228
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

5,264
kokukokuVerified publisher1.0.02 of 7See more

koku koku 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

12,019
nginx-php-fpmkokuwa0.1.42 of 2See more

nginx-php-fpm kokuwa 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/php:8.5.2-fpm-alpine3.22a2482c398d60
nghttp2@1.65.0-r0
1.68.1
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,838
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

20,403
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

4,095
mesherykubesphere-stable0.5.01 of 13See more

meshery kubesphere-stable 0.5.0

1 of the 13 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
layer5/meshery:stable-latest78a8be21bef3
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

24,690
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,710
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,422
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

113,791
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

5,654
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

2,113
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,980
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

35,050
fhir-serverlinuxforhealth0.9.11 of 2See more

fhir-server linuxforhealth 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

1,053
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

7,874

Container images carrying it

1,501 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/python:3.7eedf63967cdb
nghttp2@1.52.0-1
1.52.0-1+deb12u3
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
nghttp2@1.65.0-r0
1.68.1
2
minio/operator:v4.3.754393e03f3b2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u3
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
nghttp2@1.52.0-1
1.52.0-1+deb12u3
2
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
nghttp2@1.64.0-r0
1.68.1
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
opendatacube/ows:latest668cbb41473c
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
quickwit/quickwit:v0.8.2363ff56ce456
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
rajnandan1/kener:3.2.1930407afca731
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
uffizzi/controller:latest0344805f267b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
uselagoon/docker-host:v3.6.12c89ed939b8b
nghttp2@1.64.0-r0
1.68.1
2
vdiogov/glpi-conteiner:latest6945f84f0058
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
nghttp2@1.65.0-r0
1.68.1
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
nghttp2@1.65.0-r0
1.68.1
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
nghttp2@1.65.0-r0
1.68.1
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
2
quay.io/curl/curl:8.16.0b17b13321678
nghttp2@1.65.0-r0
1.68.1
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.