StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,790 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,790 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1246
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,440
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,993
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,034
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

4,865
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

6,514
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
matterlabs/external-node:v24.0.06cbfea4c694a
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

6,028
cidrappcidrappVerified publisher0.1.01 of 1See more

cidrapp cidrapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
svcosti/cidrapp:latest8428d87bc5d0
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

840
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,470
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

1,625
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

12,082
kube-acp-stackcloudentity2.28.02 of 7See more

kube-acp-stack cloudentity 2.28.0

2 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

21,034
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

29,920
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,827
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

25,513
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

25,807
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

29,602
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

18,374
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine54451ecb8ab3
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,185
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,501
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,197
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,636
galaxy-depscloudve1.1.11 of 7See more

galaxy-deps cloudve 1.1.1

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,581
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

16,134
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

6,204
terminalmancloudve0.3.41 of 1See more

terminalman cloudve 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/ttyd:latestd79c1c5881c0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

13,166
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,072
monitoringcluster-deploy0.3.01 of 11See more

monitoring cluster-deploy 0.3.0

1 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/grafana:12.4.1e932bd6ed0e0
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

8,219
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

9,219
clusterfactoryclusterfactory0.2.02 of 5See more

clusterfactory clusterfactory 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gitea/act_runner:0.3.1c2a169c5e998
nghttp2@1.68.0-r0
1.68.1
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

7,193
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

6,982
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,935
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

4,648
door-agentcnoVerified publisher3.0.153 of 15See more

door-agent cno 3.0.15

3 of the 15 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
library/docker:27-cli851f91d24121
nghttp2@1.64.0-r0
1.68.1
library/docker:27-dindaa3df78ecf32
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

19,454
ms-basecodedesignplus-chartsVerified publisher0.0.321 of 1See more

ms-base codedesignplus-charts 0.0.32

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nginxdemos/hello:0.4b28d1e16c676
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,292
codehubcodehubVerified publisher6.2.182 of 5See more

codehub codehub 6.2.18

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

13,312
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

5,959
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,441
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

4,691
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,983
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

14,642
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,831
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

6,214
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-zookeeper:6.1.078c190f4472c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

58,869
logstream-mastercriblio2.9.91 of 1See more

logstream-master criblio 2.9.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cribl/cribl:3.0.2762747cb6796
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

9,296
iam-zencryptexlabsVerified publisher0.12.231 of 4See more

iam-zen cryptexlabs 0.12.23

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,883
pagescrypticcode-helmchart1.0.02 of 3See more

pages crypticcode-helmchart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,242
csghubcsghubVerified publisher2.4.35 of 34See more

csghub csghub 2.4.3

5 of the 34 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
opencsghq/kubectl:latestb6d87e1048c2
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

59,452
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
opencsghq/csgship-portal:v1.2.1865814dc87a1
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

11,544
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
firefart/requesttracker:5.0.40d6249906d8c
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

15,419
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

13,944

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/minio/directpv:v4.0.84560083eb77d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/open-cluster-management/managed-serviceaccount:v0.10.0d6284bd7765a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/openshift/origin-cli:4.66722d5041b47
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
nghttp2@1.33.0-3.el8_2.2
0:1.33.0-6.el8_10.2
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.2
1
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
nghttp2@1.65.0-r0
1.68.1
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/projectquay/clair:4.9.023329c3368e4
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_7.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_7.1
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_7.1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/strimzi/operator:0.45.158c727cd2e68
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
nghttp2@1.68.0-r0
1.68.1
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
nghttp2@1.68.0-r0
1.68.1
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
nghttp2@1.68.0-r0
1.68.1
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.