StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
hyperglance-helmhyperglance-helmVerified publisher10.0.53 of 6See more

hyperglance-helm hyperglance-helm 10.0.5

3 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
hyperglance/init:wildfly467ad8491bc3
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
hyperglance/init:postgres9fd5faf1fe80
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
hyperglance/init:apacheb2f8c6d52623
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

11,171
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

7,184
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

7,902
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,770
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,460
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

12,632
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2fac502149c40
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
nghttp2@1.33.0-1.el8
0:1.33.0-6.el8_10.2

Open the chart page →

11,975
monitoring-stackict-platformVerified publisher0.4.02 of 13See more

monitoring-stack ict-platform 0.4.0

2 of the 13 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

9,597
ingress-nginxifmethod-helm-charts4.12.11 of 2See more

ingress-nginx ifmethod-helm-charts 4.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,476
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

3,181
eoloserverihuertas2021-vmartinp2021-helm0.1.03 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

27,812
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

9,032
ikigaiikigai-chartVerified publisher0.0.94 of 58See more

ikigai ikigai-chart 0.0.9

4 of the 58 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
kuberay/operator:v1.0.04e6ac8a3a2c4
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.2
library/zookeeper:3.8-temurin55d1e5b2e601
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

37,844
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/jupyterhub/configurable-http-proxy:5.1.0eb10d5bf045c
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,836
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

11,838
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

16,226
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,360
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
library/influxdb:1.12.3-datab0f9fc41ed79
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,736
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

10,542
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,157
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,457
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

18,137
kesintelVerified publisher0.8.31 of 1See more

kes intel 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
minio/kes:v0.22.255f3aef5803e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

3,570
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

5,996
intelowlintelowl-helm6.6.1-01-06-20262 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
intelowlproject/intelowl_nginx:v6.6.12f01e79b8064
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

16,558
interbtc-parachaininterlay0.4.131 of 1See more

interbtc-parachain interlay 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

3,195
polkabtc-parachaininterlay0.2.412 of 4See more

polkabtc-parachain interlay 0.2.41

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
byrnedo/alpine-curl:latest7f0599d553e2
nghttp2@1.65.0-r0
1.68.1
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

3,937
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

5,570
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

5,570
ztunnelistio-ztunnelVerified publisher1.25.01 of 1See more

ztunnel istio-ztunnel 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/ztunnel:1.25.005f3972d80a9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,497
daveit-at-mOfficialVerified publisher0.2.152 of 11See more

dave it-at-m 0.2.15

2 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

15,245
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,965
wjh-rechnerit-at-mOfficialVerified publisher1.0.41 of 1See more

wjh-rechner it-at-m 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_7.1

Open the chart page →

3,487
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

45,392
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,816
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

2,090
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,066
manyfoldjeffrescVerified publisher1.0.31 of 1See more

manyfold jeffresc 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,961
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

4,097
jellyfinjellyfin--jellyfin-helm3.0.01 of 1See more

jellyfin jellyfin--jellyfin-helm 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.717285f9cce63
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

2,967
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.2

Open the chart page →

9,853
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,856
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,256
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

7,842
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

6,648
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

6,629
image-storage-servicejtektVerified publisher0.4.33 of 4See more

image-storage-service jtekt 0.4.3

3 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

22,665
shinsei-managerjtektVerified publisher0.2.07 of 8See more

shinsei-manager jtekt 0.2.0

7 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
moreillon/group-manager:latest3caa8f710ee0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
moreillon/group-manager-front:latest5f0a38498271
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u3
moreillon/user-manager-front:v5.0.3b067dbbbb6af
nghttp2@1.52.0-1
1.52.0-1+deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

59,560
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

16,626
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,967

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/curl/curl:8.16.0b17b13321678
nghttp2@1.65.0-r0
1.68.1
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
nghttp2@1.68.0-r0
1.68.1
2
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
nghttp2@1.68.0-r0
1.68.1
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
nghttp2@1.65.0-r0
1.68.1
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
nghttp2@1.64.0-r0
1.68.1
2
1dev/server:11.9.0cd5b12fe5471
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
5200710/hadoop:3.2.3-java8092d3088a5fb
nghttp2@1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3+esm1
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
aboogie/login_test_backend:new9c41a4483ac8
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
nghttp2@1.64.0-2.el10
0:1.64.0-2.el10_1.1
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
airbyte/pod-sweeper:1.5.198d2c39d512e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
akaunting/akaunting:3.0.1552811b36ec3a
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
akeyless/base-rhel:0.0.14ba8900a0061
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
nghttp2@1.65.0-r0
1.68.1
1
aktosecurity/data-ingestion-service213aded7adc5
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
alakaganaguathoork/local-business:latest7eb27b0f4a5a
nghttp2@1.65.0-r0
1.68.1
1
alazidis/stornx:1.1.1602d4f7f090c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
allegroai/clearml:2.0.0-613713ae38f7daf
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
alpine/curl:8.12.08943e8c7e8e4
nghttp2@1.64.0-r0
1.68.1
1
alpine/git:v2.49.1c0280cf95723
nghttp2@1.65.0-r0
1.68.1
1
alpine/helm:4.1.0905a068da431
nghttp2@1.68.0-r0
1.68.1
1
alpine/k8s:1.31.106dbe6f391eda
nghttp2@1.65.0-r0
1.68.1
1
alpine/k8s:1.31.137a319b15cfc9
nghttp2@1.65.0-r0
1.68.1
1
alpine/k8s:1.32.47e1e7d5b7a96
nghttp2@1.64.0-r0
1.68.1
1
alpine/k8s:1.31.49c4976d47656
nghttp2@1.64.0-r0
1.68.1
1
alpine/k8s:1.32.3eec354133193
nghttp2@1.64.0-r0
1.68.1
1
alpine/kubectl:1.33.32c59a3f0726c
nghttp2@1.65.0-r0
1.68.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.