StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,448
of 17,781 indexed, latest versions
Container images
1,501
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,448 of 17,781 indexed charts deploy, on 1,501 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more935
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more321
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1245
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,448 by stars
ChartLatestAffected imagesRadar Score
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

5,290
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
nghttp2@1.65.0-r0
1.68.1

Open the chart page →

2,896
benchmarkoor-apiethereum-helm-chartsVerified publisher0.1.01 of 1See more

benchmarkoor-api ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

899
benchmarkoor-uiethereum-helm-chartsVerified publisher0.1.01 of 1See more

benchmarkoor-ui ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,338
powfaucetethereum-helm-chartsVerified publisher1.2.11 of 1See more

powfaucet ethereum-helm-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
pk910/powfaucet:v2-stable3dcae6a62896
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

4,456
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

20,933
spring-boot-adminevryfs-ossVerified publisher0.1.101 of 1See more

spring-boot-admin evryfs-oss 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

5,998
perliteextrim-helm-chartsVerified publisher0.1.01 of 1See more

perlite extrim-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
extrim/perlite:1.5.99cb7eb5598b6
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

1,440
fairwinds-insightsfairwinds-stableVerified publisher10.1.101 of 13See more

fairwinds-insights fairwinds-stable 10.1.10

1 of the 13 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.49ccd82364762
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

3,797
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

13,450
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

6,026
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

7,481
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3

Open the chart page →

10,741
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.3

Open the chart page →

12,454
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

7,691
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1
fireflyiii/data-importer:version-2.2.3ab52bf932546
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
nghttp2@1.64.0-1.1
1.64.0-1.1+deb13u1

Open the chart page →

4,829
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,936
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

64,489
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

8,528
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

2,475
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

2,411
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

2,293
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

4,536
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

11,835
mintakafiware0.4.71 of 1See more

mintaka fiware 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
fiware/mintaka:latestefc6793388cc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,019
orionfiware1.6.112 of 2See more

orion fiware 1.6.11

2 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

10,637
tm-forum-apifiware0.17.1519 of 19See more

tm-forum-api fiware 0.17.15

19 of the 19 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/tmforum-account:1.18.06b25aac03414
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.2

Open the chart page →

35,112
trusted-issuers-listfiware0.18.71 of 1See more

trusted-issuers-list fiware 0.18.7

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_7.1

Open the chart page →

1,701
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

7,087
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

5,292
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3

Open the chart page →

8,902
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3

Open the chart page →

5,651
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

8,041
flyte-devboxflyte0.1.01 of 13See more

flyte-devbox flyte 0.1.0

1 of the 13 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
rustfs/rustfs:1.0.0-alpha.947d49faa88c04
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

4,628
maxscalefour-allportalVerified publisher4.1.161 of 3See more

maxscale four-allportal 4.1.16

1 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
mariadb/maxscale:23.02.256c5e0908148
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,611
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
nghttp2@1.64.0-r0
1.68.1

Open the chart page →

2,438
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nghttp2@1.52.0-1
1.52.0-1+deb12u3

Open the chart page →

13,241
accumulogaffer2.2.11 of 4See more

accumulo gaffer 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Open the chart page →

9,342
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.2

Open the chart page →

11,961
pagesgary-pages1.0.02 of 3See more

pages gary-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

20,190
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

18,230
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

14,659
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

19,215
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

16,123
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3

Open the chart page →

13,551
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1

Open the chart page →

12,222

Container images carrying it

1,501 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
79
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
79
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
10
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
10
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
8
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
7
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
6
curlimages/curl:8.17.0935d9100e9ba
nghttp2@1.65.0-r0
1.68.1
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u3
6
alpine/kubectl:1.34.18413f8890d19
nghttp2@1.65.0-r0
1.68.1
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
5
library/mongo:4.44be76f674fc4
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
5
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
nghttp2@1.68.0-r0
1.68.1
5
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
4
library/mongo:5.0-focal5e15a3f014ed
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
4
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
4
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
4
library/nginx:1.27.1287ff321f9e3
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
4
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
4
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
4
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
4
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
4
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
3
curlimages/curl:8.18.0d94d07ba9e7d
nghttp2@1.68.0-r0
1.68.1
3
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
3
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
3
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
3
library/nginx:1.25:1.25.5a484819eb602
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
3
natsio/nats-box:0.19.28031d190c7ee
nghttp2@1.65.0-r0
1.68.1
3
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
xenondb/percona:5.7.330e26872a2b67
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
nghttp2@1.52.0-1
1.52.0-1+deb12u3
3
quay.io/devtron/ai-agent:0.0.16545dac92173
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
3
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
nghttp2@1.68.0-r0
1.68.1
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.2
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
3
alpine/git:2.47.2062a01ad7a0e
nghttp2@1.64.0-r0
1.68.1
2
alpine/k8s:1.32.12048f8d9c8cc7
nghttp2@1.68.0-r0
1.68.1
2
alpine/kubectl:1.35.49ccd82364762
nghttp2@1.68.0-r0
1.68.1
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.