StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,440
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,986
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,006
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

4,858
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

6,487
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
matterlabs/external-node:v24.0.06cbfea4c694a
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

5,550
cidrappcidrappVerified publisher0.1.01 of 1See more

cidrapp cidrapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
svcosti/cidrapp:latest8428d87bc5d0
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

840
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,470
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

1,618
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

12,021
kube-acp-stackcloudentity2.28.02 of 7See more

kube-acp-stack cloudentity 2.28.0

2 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

20,936
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

29,922
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,831
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

25,152
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

25,454
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

29,594
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Open the chart page →

18,256
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine54451ecb8ab3
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

2,185
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,505
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,176
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

11,640
galaxy-depscloudve1.1.11 of 7See more

galaxy-deps cloudve 1.1.1

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

10,543
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

16,117
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,994
terminalmancloudve0.3.41 of 1See more

terminalman cloudve 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cloudve/ttyd:latestd79c1c5881c0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

13,170
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

7,521
monitoringcluster-deploy0.3.01 of 11See more

monitoring cluster-deploy 0.3.0

1 of the 11 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
grafana/grafana:12.4.1e932bd6ed0e0
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

8,185
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,806
clusterfactoryclusterfactory0.2.02 of 5See more

clusterfactory clusterfactory 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gitea/act_runner:0.3.1c2a169c5e998
nghttp2@1.68.0-r0
1.68.1
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

7,136
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

6,926
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,918
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

4,616
door-agentcnoVerified publisher3.0.153 of 15See more

door-agent cno 3.0.15

3 of the 15 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
library/docker:27-cli851f91d24121
nghttp2@1.64.0-r0
1.68.1
library/docker:27-dindaa3df78ecf32
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

19,380
ms-basecodedesignplus-chartsVerified publisher0.0.321 of 1See more

ms-base codedesignplus-charts 0.0.32

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
nginxdemos/hello:0.4b28d1e16c676
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

1,292
codehubcodehubVerified publisher6.2.182 of 5See more

codehub codehub 6.2.18

2 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

13,286
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

5,958
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,251
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Open the chart page →

4,682
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

2,994
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

14,587
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,814
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

6,183
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
confluentinc/cp-zookeeper:6.1.078c190f4472c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

58,856
logstream-mastercriblio2.9.91 of 1See more

logstream-master criblio 2.9.9

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
cribl/cribl:3.0.2762747cb6796
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

9,293
iam-zencryptexlabsVerified publisher0.12.231 of 4See more

iam-zen cryptexlabs 0.12.23

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

3,872
pagescrypticcode-helmchart1.0.02 of 3See more

pages crypticcode-helmchart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,233
csghubcsghubVerified publisher2.4.35 of 34See more

csghub csghub 2.4.3

5 of the 34 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
opencsghq/kubectl:latestb6d87e1048c2
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

59,131
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
opencsghq/csgship-portal:v1.2.1865814dc87a1
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

11,402
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
firefart/requesttracker:5.0.40d6249906d8c
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

14,206
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

13,937

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dongjiang1989/lxcfs:v6.0.34bf9ae391948
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
dragonflyoss/client:v0.1.82edf3e921f4e0
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
dremio/dremio-oss:24.1.080ed2e3b7c43
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
drpcorg/dshackle:0.54.08858fae1859d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
drumsergio/genieacs:1.2.16.028244054e1bf
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
dserio83/velero-api:0.3.16b3d9115fee2
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
dserio83/velero-watchdog:0.1.8d5deae589229
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
duck1123/cert-downloader:latest0e29f19fa67c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
duck1123/lnd-fileserver:latest9d6fb247b714
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
dunglas/mercure:v0.24.080fcb704a741
nghttp2@1.68.0-r0
1.68.1
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
nghttp2@1.65.0-r0
1.68.1
1
elastic/apm-server:7.17.6c7a1c63257d0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
elastictranscoder/media:627e21dc963ab3858c6b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elastictranscoder/media-storage:f6d861a026208b8c2359
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elautoestopista/aeneabot:4.2.1125ba620d528
nghttp2@1.68.0-r0
1.68.1
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
emqx/ecp-ui:2.5.1e33e9816f147
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
emqx/emqx:5.8.935b46f7aa7a0
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
engrmth/bnkr:2.1.06d8464e6f0e8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
erenozcan17/react_frontend:v4.56e1b14973f9b
nghttp2@1.65.0-r0
1.68.1
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1
1
escaping/core-keeper-dedicated:latest87fa79255962
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
esphome/esphome:2024.3.09ab8cc88b28c
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
esphome/esphome:2024.12.2b2c6322700ac
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
esphome/esphome:2025.3.0def8b6e4f517
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
esteban1930/frontend-1:1.8.0f9078279632c
nghttp2@1.65.0-r0
1.68.1
1
etherpad/etherpad:2.7.2b723fe5f2594
nghttp2@1.68.0-r0
1.68.1
1
evoapicloud/evolution-manager:latestcbfeb314afb9
nghttp2@1.65.0-r0
1.68.1
1
extrim/perlite:1.5.99cb7eb5598b6
nghttp2@1.64.0-r0
1.68.1
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
felipecs8/app-db-connection-test:v129e06c9c6385
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
filiparag/hetzner_ddns:1.0.15a9cbae7997c
nghttp2@1.65.0-r0
1.68.1
1
firefart/requesttracker:5.0.40d6249906d8c
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
fiware/mintaka:0.7.092a3c5cf43c0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
fiware/mintaka:latestefc6793388cc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
fiware/orion-ld:1.10.03c490a746f65
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
flanksource/batch-runner:v1.0.44689687a7cf95
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
flashcatcloud/categraf:latest42e6ab16472e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
fluent/fluent-bit:4.0.4ca08b7d2df5b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
fluent/fluent-bit:4.0-debuge76397ef3983
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
flyway/flyway:9.1545b5d7cdc75a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
fosrl/pangolin:1.13.0c32ad797ab96
nghttp2@1.68.0-r0
1.68.1
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.