StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,233
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
hazelcast/management-center:5.3.2f9d34300d330
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

28,212
anchore-admission-controlleranchore-charts0.8.51 of 2See more

anchore-admission-controller anchore-charts 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

7,559
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,233
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,872
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

42,345
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

5,516
ansible-playbook-operatoransible-playbook-operatorVerified publisher0.1.71 of 1See more

ansible-playbook-operator ansible-playbook-operator 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,340
antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher0.2.01 of 1See more

antigenic-docuseal-helm-chart antigenic-docuseal-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
docuseal/docuseal:2.4.17493fd7f6728
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,766
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

2,454
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

3,201
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,132
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

2,947
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

6,227
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

19,784
app-mobilityappmo0.1.02 of 5See more

app-mobility appmo 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,520
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,056
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

4,002
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
ghcr.io/appscode/inbox-server:latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

15,707
inbox-uiappscodeVerified publisher2026.9.111 of 1See more

inbox-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

840
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

17,110
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

2,404
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

912
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

4,043
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

2,568
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

37,184
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

3,310
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

4,899
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-6.el8_10.2

Open the chart page →

2,902
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

9,847
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

7,521
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

7,338
arlas-aiasarlas-stackVerified publisher28.8.07 of 22See more

arlas-aias arlas-stack 28.8.0

7 of the 22 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

40,411
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

23,407
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

3,568
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

22,677
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

14,725
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

9,407
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

12,799
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

10,101
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3

Open the chart page →

18,331
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,982
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

5,368
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
1.52.0-1+deb12u3
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

42,460
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

13,986
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

31,807
celestia-localastria9.0.01 of 2See more

celestia-local astria 9.0.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

3,281
sequencerastria4.0.01 of 3See more

sequencer astria 4.0.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

6,239
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

8,555
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

6,948

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-kafka:7.4.4c0224a1adf7a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
consensys/teku:25.4.1bf6ecd2ea716
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
cortezaproject/corteza:2024.9.08eb7a26605c9
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
countly/countly-server:25.05.4e3c238248f99
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
nghttp2@1.65.0-r0
1.68.1
1
craftypath/sops-operator:v0.8.0402a0024c732
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
cribl/cribl:3.0.2762747cb6796
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
cspconsole/config-provider:1.0.365524a26a6c23
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
cspconsole/report-collector:1.0.15839750248193b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
ctron/hawkbit-operator:0.1.48fdea8f76499
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
curlimages/curl:8.12.194e9e444bcba
nghttp2@1.64.0-r0
1.68.1
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
dannielkil/book-frontend:latest937993927694
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
daskdev/dask-notebook:1.1.0052630f5ca04
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
datamate/seafile-professional:11.0.202dd66b722464
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
deconzcommunity/deconz:2.29.2062de2362641
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
dellcloud/category:distributed02fc234353a9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
dellcloud/pages:1.04d2eb25b9225
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
dependencytrack/frontend:4.14.200560b57a6cf
nghttp2@1.68.0-r0
1.68.1
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
diygod/rsshub:2025-11-097a6312cac0d5
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
djjudas21/nova-exporter:0.0.10e9094580885c
nghttp2@1.65.0-r0
1.68.1
1
dniel/api-posts:master45a667852f2a
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
dobtc/bitcoin:25.1a870f7cb1105
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
docuseal/docuseal:2.4.17493fd7f6728
nghttp2@1.68.0-r0
1.68.1
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
domainmod/domainmod:4.23.04017bfe4c597
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.