StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,790 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,790 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1246
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,571

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bmeares/meerschaum:2.8.48e9c5bacaa82
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
bnjbvr/kresus:0.22.137e216b182c8
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
boky/postfix:5.1.0aafc77238423
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
boky/postfix:4.4.0f3f247fd4252
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
bsgrigorov/helm-operator:latest45ab095f09c8
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
budibase/database:2.1.0d90f656261c9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
byrnedo/alpine-curl:latest7f0599d553e2
nghttp2@1.65.0-r0
1.68.1
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
nghttp2@1.65.0-r0
1.68.1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
castlemock/castlemock:latestb7f3f1527ba9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
castopod/castopod:1.12.101fd37280cbb2
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
castopod/castopod:1.15.54e4f0440520f
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
nghttp2@1.39.2-lp151.3.3.1
1.68.1-1.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
nghttp2@1.39.2-lp151.3.3.1
1.68.1-1.1
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
nghttp2@1.64.0-r0
1.68.1
1
chetangautamm/repo:sipp.v3e7f7049e1544
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
cheveo/azp-agent:1.0.282240f890884
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
nghttp2@1.65.0-r0
1.68.1
1
chriseaton/adventureworks:latest54c3384ce701
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
circleci/runner:launch-agent9bdc62f02162
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
ckulka/baikal:0.10.1-nginx434bdd162247
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
cleveritcz/opencve:1.5.0c75c1636e0b7
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_7.1
1
cloudposse/bastion:latest0d9507e8a760
nghttp2@1.64.0-r0
1.68.1
1
cloudve/ttyd:latestd79c1c5881c0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
nghttp2@1.65.0-r0
1.68.1
1
cm2network/squad:latest8cba47f53df5
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
cockroachdb/cockroach:v22.2.91116820f4134
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
cockroachdb/cockroach-operator:v2.1.0983312754620
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
coderenvs/coder-service:1.44.61deffc4670e6
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
coderenvs/timescale:1.44.676fd37fe6830
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
codetogether/codetogether:latest4348c8a38752
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_7.1
1
collabora/code:24.04.13.2.101dc4ab83977
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
collabora/code:23.05.10.1.105299b452f7f
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
cometbft/cometbft:v0.38.1722c2ac018f40
nghttp2@1.64.0-r0
1.68.1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.