StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,453
of 17,803 indexed, latest versions
Container images
2,605
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,453 of 17,803 indexed charts deploy, on 2,605 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,699
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0900
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,453 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,569
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,879
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,160

Container images carrying it

2,605 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kubesec/kubesec:latest025a365d9f18
zlib@1.3.1-r1
1.3.2-r0
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
zlib@1.3.1-r1
1.3.2-r0
1
kubeshop/testkube-logs-server:latest094186b19698
zlib@1.3.1-r2
1.3.2-r0
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
zlib@1:1.2.13.dfsg-1
no fix listed
1
kubeshop/tracetest:v1.7.173d7e3a2db43
zlib@1.3.1-r1
1.3.2-r0
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
zlib@1.3.1-r2
1.3.2-r0
1
kuzwolka/aws9:main1ad759b961b1
zlib@1:1.2.13.dfsg-1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
zlib@1:1.2.13.dfsg-1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
zlib@1:1.2.13.dfsg-1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
zlib@1:1.2.13.dfsg-1
no fix listed
1
kvalitetsit/kitargus:2026-03-09-091234-10013c4c5cde2d9371c
zlib@1.3.1-r2
1.3.2-r0
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
kyovint/kyoimgusers:1.0.080084149156e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
labs64/auditflowc7b26d3ca11c
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
labs64/payment-gateway:0.0.10c66feefca17
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
labs64/traefik-authproxy:0.0.3dfc6086dfbce
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
laly9999/node-app:1dd0e503913e1
zlib@1:1.2.13.dfsg-1
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
zlib@1:1.2.13.dfsg-1
no fix listed
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
zlib@1:1.2.13.dfsg-1
no fix listed
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
zlib@1:1.2.13.dfsg-1
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
zlib@1:1.2.13.dfsg-1
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
zlib@1:1.2.13.dfsg-1
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
zlib@1:1.2.13.dfsg-1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
langgenius/dify-sandbox:0.2.15750e1111426e
zlib@1:1.3.dfsg+really1.3.1-3
no fix listed
1
langgenius/dify-web:1.16.187dd47e4e28f
zlib@1.3.1-r2
1.3.2-r0
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
zlib@1.3.1-r2
1.3.2-r0
1
langgenius/dify-web:1.0.0d64914ff0d6d
zlib@1.3.1-r1
1.3.2-r0
1
layer5/meshery:stable-latest78a8be21bef3
zlib@1.3.1-r2
1.3.2-r0
1
leantime/leantime:3.3.3ad4bfb0699d3
zlib@1.3.1-r1
1.3.2-r0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
zlib@1.3.1-r1
1.3.2-r0
1
lib42/jackett:latesta55596cda383
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/alpine:3.23.325109184c71b
zlib@1.3.1-r2
1.3.2-r0
1
library/buildpack-deps:scmac978b783657
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/caddy:2.9-alpineb4e3952384eb
zlib@1.3.1-r1
1.3.2-r0
1
library/cassandra:4.0093ee8ee5eb2
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/convertigo:8.4.3ae605bfcda05
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
library/couchdb:3.4.22817ad50b5c5
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/debian:12.5-slim67f3931ad8cb
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/debian:bookworm6ebd97fa83de
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/debian:12.12-slimd5d3f9c23164
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/debian:latestf324c7ff5432
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/docker:28.5.2-dind2a232a42256f
zlib@1.3.1-r2
1.3.2-r0
1
library/docker:27-cli851f91d24121
zlib@1.3.1-r2
1.3.2-r0
1
library/docker:27-dindaa3df78ecf32
zlib@1.3.1-r2
1.3.2-r0
1
library/docker:26.1-dinddd43b430341a
zlib@1.3.1-r1
1.3.2-r0
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/eclipse-mosquitto:2.0.2021421af7b32b
zlib@1.3.1-r1
1.3.2-r0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.