StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,451
of 17,790 indexed, latest versions
Container images
1,503
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,451 of 17,790 indexed charts deploy, on 1,503 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1246
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,451 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,571

Container images carrying it

1,503 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dremio/dremio-oss:24.1.080ed2e3b7c43
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
drpcorg/dshackle:0.54.08858fae1859d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
drumsergio/genieacs:1.2.16.028244054e1bf
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
dserio83/velero-api:0.3.16b3d9115fee2
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
dserio83/velero-watchdog:0.1.8d5deae589229
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
duck1123/cert-downloader:latest0e29f19fa67c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
duck1123/lnd-fileserver:latest9d6fb247b714
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
1
dunglas/mercure:v0.24.080fcb704a741
nghttp2@1.68.0-r0
1.68.1
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
nghttp2@1.65.0-r0
1.68.1
1
elastic/apm-server:7.17.6c7a1c63257d0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
elastictranscoder/media:627e21dc963ab3858c6b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elastictranscoder/media-storage:f6d861a026208b8c2359
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
elautoestopista/aeneabot:4.2.1125ba620d528
nghttp2@1.68.0-r0
1.68.1
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
emqx/ecp-ui:2.5.1e33e9816f147
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
emqx/emqx:5.8.935b46f7aa7a0
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
engrmth/bnkr:2.1.06d8464e6f0e8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
erenozcan17/react_frontend:v4.56e1b14973f9b
nghttp2@1.65.0-r0
1.68.1
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1
1
escaping/core-keeper-dedicated:latest87fa79255962
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
esphome/esphome:2024.3.09ab8cc88b28c
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
1
esphome/esphome:2024.12.2b2c6322700ac
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
esphome/esphome:2025.3.0def8b6e4f517
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
esteban1930/frontend-1:1.8.0f9078279632c
nghttp2@1.65.0-r0
1.68.1
1
etherpad/etherpad:2.7.2b723fe5f2594
nghttp2@1.68.0-r0
1.68.1
1
evoapicloud/evolution-manager:latestcbfeb314afb9
nghttp2@1.65.0-r0
1.68.1
1
extrim/perlite:1.5.99cb7eb5598b6
nghttp2@1.64.0-r0
1.68.1
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
1
felipecs8/app-db-connection-test:v129e06c9c6385
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
filiparag/hetzner_ddns:1.0.15a9cbae7997c
nghttp2@1.65.0-r0
1.68.1
1
firefart/requesttracker:5.0.40d6249906d8c
nghttp2@1.52.0-1
1.52.0-1+deb12u3
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
fiware/mintaka:0.7.092a3c5cf43c0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
fiware/mintaka:latestefc6793388cc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
1
fiware/orion-ld:1.10.03c490a746f65
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
1
flanksource/batch-runner:v1.0.44689687a7cf95
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
flashcatcloud/categraf:latest42e6ab16472e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
1
fluent/fluent-bit:4.0.4ca08b7d2df5b
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
fluent/fluent-bit:4.0-debuge76397ef3983
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
1
flyway/flyway:9.1545b5d7cdc75a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
1
fosrl/pangolin:1.13.0c32ad797ab96
nghttp2@1.68.0-r0
1.68.1
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.