StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,450
of 17,797 indexed, latest versions
Container images
2,594
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,450 of 17,797 indexed charts deploy, on 2,594 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,686
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0902
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,450 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,594 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
esphome/esphome:2026.9.09959730a04c7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
zlib@1:1.2.13.dfsg-1
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
zlib@1:1.2.13.dfsg-1
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
zlib@1:1.2.13.dfsg-1
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
esteban1930/frontend-1:1.8.0f9078279632c
zlib@1.3.1-r2
1.3.2-r0
1
ethereum/client-go:v1.15.101f36ca5922a5
zlib@1.3.1-r2
1.3.2-r0
1
ethereum/client-go:v1.16.532b878e4144a
zlib@1.3.1-r2
1.3.2-r0
1
ethereum/client-go:v1.14.8886ec69b35b0
zlib@1.3.1-r1
1.3.2-r0
1
ethersphere/bee:2.2.0a884fd84b72f
zlib@1:1.2.13.dfsg-1
no fix listed
1
ethersphere/beekeeper:lateste4cda693ed63
zlib@1:1.2.13.dfsg-1
no fix listed
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
zlib@1.3.1-r2
1.3.2-r0
1
ethpandaops/assertoor:latest1efa2fba6711
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ethpandaops/buildoor:maina51b9a1a770c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ethpandaops/dora:master2381ea793a12
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ethpandaops/eleel:mainb8f1b707aee0
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ethpandaops/ethereumjs:masterfb84b718500f
zlib@1.3.1-r2
1.3.2-r0
1
ethpandaops/forky:debian-latestc937f4ba737c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ethpandaops/observoor:masterc7e5055defcb
zlib@1:1.2.13.dfsg-1
no fix listed
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ethpandaops/spamoor:latest5f731b20ec50
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ethpandaops/xatu-cbt-api:latestf7dec2e07091
zlib@1.3.1-r2
1.3.2-r0
1
evcc/evcc:0.300.8ddf2a25afce5
zlib@1.3.1-r2
1.3.2-r0
1
evoapicloud/evolution-manager:latestcbfeb314afb9
zlib@1.3.1-r2
1.3.2-r0
1
extrim/perlite:1.5.99cb7eb5598b6
zlib@1.3.1-r2
1.3.2-r0
1
factoriotools/factorio:stablec6092b912bd1
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
factoriotools/factorio:lateste9227748c507
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
falcosecurity/event-generator:latest932956d86c99
zlib@1:1.2.13.dfsg-1
no fix listed
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
zlib@1:1.2.13.dfsg-1
no fix listed
1
falcosecurity/falcosidekick:2.32.01976da721518
zlib@1.3.1-r2
1.3.2-r0
1
fallenbagel/jellyseerr:latest4538137bc5af
zlib@1.3.1-r2
1.3.2-r0
1
featureformcom/quickstart-loader:latest82396f8fb5e8
zlib@1.3.1-r1
1.3.2-r0
1
featurehub/dacha2:1.9.1c8d5551b5e40
zlib@1.3.1-r2
1.3.2-r0
1
featurehub/edge:1.9.198ad426737f6
zlib@1.3.1-r2
1.3.2-r0
1
featurehub/mr:1.9.1477d8bf771a9
zlib@1.3.1-r2
1.3.2-r0
1
federid/webhook:0.1.0fbfb7c6510a7
zlib@1:1.2.13.dfsg-1
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
zlib@1:1.2.13.dfsg-1
no fix listed
1
felipecs8/conversor-temperatura:v1f945423be36d
zlib@1.3.1-r2
1.3.2-r0
1
felipecs8/landing-page:v1db6d44e325a1
zlib@1.3.1-r2
1.3.2-r0
1
ffutop/ddc-ph-kafka-egress:latest319d94c8481a
zlib@1.3.1-r2
1.3.2-r0
1
ffutop/ddc-ph-kafka-ingress:latest15832d4f19be
zlib@1.3.1-r2
1.3.2-r0
1
ffutop/ddc-transport-udp-receive:latest651ca530d787
zlib@1.3.1-r2
1.3.2-r0
1
ffutop/ddc-transport-udp-send:latest4222eb5ee847
zlib@1.3.1-r2
1.3.2-r0
1
filiparag/hetzner_ddns:1.0.15a9cbae7997c
zlib@1.3.1-r2
1.3.2-r0
1
firefart/requesttracker:5.0.40d6249906d8c
zlib@1:1.2.13.dfsg-1
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
zlib@1:1.2.13.dfsg-1
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.