StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,453
of 17,803 indexed, latest versions
Container images
2,605
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,453 of 17,803 indexed charts deploy, on 2,605 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,699
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0900
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,453 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,569
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,879
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,160

Container images carrying it

2,605 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/nextcloud:34.0.4-apachede4ad9389386
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/nginx:1.27.409369da6b103
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/nginx:1.291881968aff6f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/nginx:1.27-alpine65645c7bb6a0
zlib@1.3.1-r2
1.3.2-r0
1
library/nginx:1.276784fb0834aa
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/nginx:1.25.167f9a4f10d14
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/nginx:1.25.49ff236ed47fe
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/nginx:1.31a53fc6c27208
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/nginx:1.28-alpinea8b39bd9cf0f
zlib@1.3.1-r2
1.3.2-r0
1
library/nginx:1.29.3-alpineb3c656d55d7a
zlib@1.3.1-r2
1.3.2-r0
1
library/nginx:1.27.3fb197595ebe7
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/node:22-bookworm-slim83f487e0a634
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/node:18-alpine8d6421d663b4
zlib@1.3.1-r2
1.3.2-r0
1
library/node:208f693eaa7e0a
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/node:latestf5d1cc40abc1
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/php:8.4-fpm59fa733c9af6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/php:8.5.2-fpm-alpine3.22a2482c398d60
zlib@1.3.1-r2
1.3.2-r0
1
library/phpmyadmin:5.2.3-apacheadc486045303
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:18.0073e7c8b84e2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:17.4304ab8135187
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/postgres:18.43a82e1f56c8f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:18.1-alpine3.2144d837eb4c2e
zlib@1.3.1-r2
1.3.2-r0
1
library/postgres:16.11468e1f126ca5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:16.6557fea37a744
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/postgres:17.5-alpine6567bca8d7bc
zlib@1.3.1-r2
1.3.2-r0
1
library/postgres:18.369e8582b781c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:15.186eb0add3b77c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:17.4-alpine7062a2109c4b
zlib@1.3.1-r2
1.3.2-r0
1
library/postgres:12-alpine7c8f48705831
zlib@1.3.1-r2
1.3.2-r0
1
library/postgres:17.2-alpine7e5df973a748
zlib@1.3.1-r2
1.3.2-r0
1
library/postgres:15.38775adb39f0d
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/postgres:18.48ff36f3c6637
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:18.3a9abf4275f9e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:17.5aadf2c0696f5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:13.12ced3ba927f4c
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/postgres:15.18-bookworme8db9bd3e9e1
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/postgres:14.22eba8ddbdd837
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:17.10ebba4f4de37f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/postgres:17.6-alpineef257d85f76e
zlib@1.3.1-r2
1.3.2-r0
1
library/postgres:17.5-bookwormfbcea1bd13b6
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/python:3.8-alpine3d93b1f77efc
zlib@1.3.1-r1
1.3.2-r0
1
library/python:3.1070c9cc675605
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/python:3.11-slim9534e5a8e315
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/python:3.8d41127070014
zlib@1:1.2.13.dfsg-1
no fix listed
1
library/python:3.9da5aee29682d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
library/python:3.14.3-alpine3.23faee120f7885
zlib@1.3.1-r2
1.3.2-r0
1
library/rabbitmq:3.12-management-alpine0b44fbcc3a4b
zlib@1.3.1-r1
1.3.2-r0
1
library/rabbitmq:4.2.87561d672fae4
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
library/rabbitmq:3.12-alpine97907aceae0a
zlib@1.3.1-r1
1.3.2-r0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.