StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,450
of 17,797 indexed, latest versions
Container images
2,594
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,450 of 17,797 indexed charts deploy, on 2,594 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,686
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0902
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,450 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,594 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
drumsergio/duplicacy-container:0.1.0dd3ee9703969
zlib@1.3.1-r2
1.3.2-r0
1
drumsergio/duplicacy-exporter:0.3.4ca3476077215
zlib@1.3.1-r2
1.3.2-r0
1
drumsergio/genieacs:1.2.16.028244054e1bf
zlib@1:1.2.13.dfsg-1
no fix listed
1
drumsergio/pumperly:1.4.885bbc3915e9e
zlib@1.3.1-r2
1.3.2-r0
1
dserio83/velero-api:0.3.16b3d9115fee2
zlib@1:1.2.13.dfsg-1
no fix listed
1
dserio83/velero-watchdog:0.1.8d5deae589229
zlib@1:1.2.13.dfsg-1
no fix listed
1
duck1123/dinsro:latest9568c5961d5d
zlib@1.3.1-r2
1.3.2-r0
1
durellirsd/security-smells-api:v17398aca4fc2e
zlib@1.3.1-r1
1.3.2-r0
1
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
zlib@1.3.1-r2
1.3.2-r0
1
dwdraju/alpine-curl-jq:latest83bd9be2b14b
zlib@1.3.1-r1
1.3.2-r0
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
dzikoysk/reposilite:3.6.390de4c8e6c0e
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
eceasy/cli-proxy-api:v7.3.3f9abbf3fa5fe
zlib@1:1.2.13.dfsg-1
no fix listed
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
zlib@1.3.1-r2
1.3.2-r0
1
eclipseaerios/hlo-allocator:v3.0.03cc1d94cfe96
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
zlib@1.3.1-r2
1.3.2-r0
1
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
zlib@1:1.2.13.dfsg-1
no fix listed
1
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
eftechcombr/glpi:php-fpm-12.0.0-rc27573fa8503ee
zlib@1.3.1-r2
1.3.2-r0
1
eftechcombr/glpi:nginx-12.0.0-rc2e5db0c32f930
zlib@1.3.1-r2
1.3.2-r0
1
eginnovations/agent:7.5.4e4dfe242fe9f
zlib@1:1.3.dfsg+really1.3.1-1ubuntu2
no fix listed
1
elastiflow/flow-collector:7.26.0fee67842e16b
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
elautoestopista/aeneabot:4.2.1125ba620d528
zlib@1.3.1-r2
1.3.2-r0
1
elautoestopista/raponchi:0.3.0b6f74db9fc81
zlib@1.3.1-r1
1.3.2-r0
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
emirozbir/dashdns-admission-webhook:v2.0.56801ba2a3fc3
zlib@1.3.1-r2
1.3.2-r0
1
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
zlib@1.3.1-r1
1.3.2-r0
1
emqxecp/otelcol:2.5.04c31d9bec846
zlib@1.3.1-r1
1.3.2-r0
1
emqx/ecp-ui:2.5.1e33e9816f147
zlib@1:1.2.13.dfsg-1
no fix listed
1
emqx/emqx:5.8.935b46f7aa7a0
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
emqx/emqx-ee:4.4.38d48360ed86f4
zlib@1.3.1-r2
1.3.2-r0
1
emqx/emqx-enterprise:6.3.03b6d9c0c4199
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
zlib@1.3.1-r2
1.3.2-r0
1
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
erenozcan17/go_backend:v4.250b4f23422b6
zlib@1.3.1-r2
1.3.2-r0
1
erenozcan17/react_frontend:v4.56e1b14973f9b
zlib@1.3.1-r2
1.3.2-r0
1
erigontech/erigon:latest2252efdf9abe
zlib@1:1.2.13.dfsg-1
no fix listed
1
erigontech/erigon:v2.61.288706754b627
zlib@1:1.2.13.dfsg-1
no fix listed
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
zlib@1.3.1-r2
1.3.2-r0
1
erlangsolutions/mongooseim:6.6.0cc5bf032931f
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
erudikaltd/para:latest_stable235e0bc53da2
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
erudikaltd/scoold:1.66.0949c56b57e8f
zlib@1.3.1-r2
1.3.2-r0
1
escaping/core-keeper-dedicated:latest87fa79255962
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.