StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,447
of 17,787 indexed, latest versions
Container images
1,500
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,447 of 17,787 indexed charts deploy, on 1,500 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more934
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more321
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1245
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,447 by stars
ChartLatestAffected imagesRadar Score
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
kuzwolka/aws9:news3e8880fbbb96
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
kuzwolka/aws9:blog4a7707410bf1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
kuzwolka/aws9:shop84a9d9766345
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

18,344
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,268
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
infiniflow/infinity:v0.7.0992c87a68612
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,823
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

2,738
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

6,297
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

20,671
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

7,190
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

5,059
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,145
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

13,459
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

15,253
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
sysnet4admin/colosseum-prm:log5802bfcd7fed
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

26,996
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

19,229
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

8,323
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.61 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,720
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

3,071
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.02 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
pagesbrixton-pages1.0.02 of 3See more

pages brixton-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
ombibryanalves0.4.01 of 1See more

ombi bryanalves 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

10,776
plexbryanalves0.5.01 of 1See more

plex bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

6,707
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

14,352
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,869
caddycaddyVerified publisher0.0.41 of 1See more

caddy caddy 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/caddy:2.11.2-alpine834468128c76
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,677
pagescamden-pages1.0.02 of 3See more

pages camden-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,001
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

88,335
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,311
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

5,039
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

5,886
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,776
pagescarina-pages1.0.02 of 3See more

pages carina-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
pagescarmel-pages-dell1.0.02 of 3See more

pages carmel-pages-dell 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
cassandra-clustercassandra-clusterVerified publisher0.1.01 of 1See more

cassandra-cluster cassandra-cluster 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/cassandra:3.11.10b095ff3248c6
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

9,473
catalyst-agentscatalyst-agents0.1.301 of 18See more

catalyst-agents catalyst-agents 0.1.30

1 of the 18 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

15,027
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,389
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,776
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,338
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

15,371
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,338
clechaosnative0.2.71 of 6See more

cle chaosnative 0.2.7

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
litmuschaos/mongo:4.2.899961210d467
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

16,389
charon-relaycharonOfficialVerified publisher0.8.01 of 2See more

charon-relay charon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

4,396
helioscharonVerified publisher0.1.51 of 1See more

helios charon 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
obolnetwork/helios:e10e753cb7e97d39d46
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,087
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,778
kitchenowlchart-kitchenowl0.1.122 of 2See more

kitchenowl chart-kitchenowl 0.1.12

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
tombursch/kitchenowl-web:v0.7.8517f808eee66
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

4,803
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

12,779
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,483
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,423

Container images carrying it

1,500 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
artur9010/wait-for:v1.0.06b4de3ce8b0e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
arunvelsriram/utils:latest655ad18fd8d6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
assistiot/open_api_backend:1.1.230812ba93555
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
atlassian/confluence-server:7.10.03b9222ab32ef
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
atlassian/jira-software:8.14.037bc46cbec1a
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
1
atlassian/jira-software:9.7.264a75aa4ec4e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
avinash263/pyredis263:latestaa2b8727f1a6
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
avzini/web-app:latestf40b30210ed0
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
nghttp2@1.68.0-r0
1.68.1
1
baserow/backend:1.31.1e0b3c8130b91
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
baserow/baserow:1.30.1df0c42eb67e8
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
beopenit/door-helm:v3.0.1b4d9f9bee224
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
beyzkaya/blog-frontend:v1.0.0bf412d75c510
nghttp2@1.65.0-r0
1.68.1
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/git:latest4b08d0c5af8d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/kubectl:1.301249fc292e84
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/kubectl:1.3164614ef8290f
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/mongodb:latestb0652af9c8d0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.