StackRadar

CVE-2026-27135

High

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,453
of 17,787 indexed, latest versions
Container images
1,505
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,453 of 17,787 indexed charts deploy, on 1,505 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+11 more1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.52.0-1+deb12u3+3 more936
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+13 more0:1.33.0-6.el8_10.2, 0:1.43.0-6.el9_7.1, 0:1.64.0-2.el10_1.1, 1.64.0-150700.3.3.1+1 more322
nghttp2apk1.57.0-r0, 1.64.0-r0, 1.65.0-r0, 1.68.0-r01.68.1247
OSV records
ALPINE-CVE-2026-27135DEBIAN-CVE-2026-27135RHSA-2026:7666RHSA-2026:7667RHSA-2026:7668RLSA-2026:7667RLSA-2026:7668UBUNTU-CVE-2026-27135openSUSE-SU-2026:10437-1SUSE-SU-2026:1074-1
Also known as
RHSA-2026:8538, RHSA-2026:8539, RHSA-2026:8540, RHSA-2026:8541, RHSA-2026:8545, RHSA-2026:8547, RHSA-2026:8548, USN-8233-1

Charts affected

1,453 by stars
ChartLatestAffected imagesRadar Score
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2

Open the chart page →

3,697
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27135.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
nghttp2@1.68.0-r0
1.68.1

Open the chart page →

1,571

Container images carrying it

1,505 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
79
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
79
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
10
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
10
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
8
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3
7
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
6
curlimages/curl:8.17.0935d9100e9ba
nghttp2@1.65.0-r0
1.68.1
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u3
6
alpine/kubectl:1.34.18413f8890d19
nghttp2@1.65.0-r0
1.68.1
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
5
library/mongo:4.44be76f674fc4
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
5
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
nghttp2@1.68.0-r0
1.68.1
5
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.3
4
library/mongo:5.0-focal5e15a3f014ed
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
4
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
4
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
4
library/nginx:1.27.1287ff321f9e3
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
4
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
4
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
4
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm3
4
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
4
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
3
curlimages/curl:8.18.0d94d07ba9e7d
nghttp2@1.68.0-r0
1.68.1
3
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
3
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3
3
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1
3
library/nginx:1.25:1.25.5a484819eb602
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
3
natsio/nats-box:0.19.28031d190c7ee
nghttp2@1.65.0-r0
1.68.1
3
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
xenondb/percona:5.7.330e26872a2b67
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.3+esm1
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
nghttp2@1.52.0-1
1.52.0-1+deb12u3
3
quay.io/devtron/ai-agent:0.0.16545dac92173
nghttp2@1.52.0-1+deb12u1
1.52.0-1+deb12u3
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
3
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.3
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nghttp2@1.52.0-1+deb12u2
1.52.0-1+deb12u3
3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
nghttp2@1.68.0-r0
1.68.1
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.2
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.2
3
alpine/git:2.47.2062a01ad7a0e
nghttp2@1.64.0-r0
1.68.1
2
alpine/k8s:1.32.12048f8d9c8cc7
nghttp2@1.68.0-r0
1.68.1
2
alpine/kubectl:1.35.49ccd82364762
nghttp2@1.68.0-r0
1.68.1
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.