StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,453
of 17,803 indexed, latest versions
Container images
2,605
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,453 of 17,803 indexed charts deploy, on 2,605 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,699
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0900
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,453 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,569
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,879
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,160

Container images carrying it

2,605 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
qmcgaw/gluetun:v3.41.11a5bf4b4820a
zlib@1.3.1-r2
1.3.2-r0
1
qmcgaw/gluetun:v3.40.02b42bfa04675
zlib@1.3.1-r1
1.3.2-r0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
quickwit/quickwit:v0.8.1d29332bdadcc
zlib@1:1.2.13.dfsg-1
no fix listed
1
qxip/qryn:3.2.3977acc9c7a9fd
zlib@1:1.2.13.dfsg-1
no fix listed
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
zlib@1.3.1-r2
1.3.2-r0
1
rancher/local-path-provisioner:v0.0.329289da488b07
zlib@1.3.1-r2
1.3.2-r0
1
rancher/local-path-provisioner:v0.0.309b9148811700
zlib@1.3.1-r1
1.3.2-r0
1
readysettech/sqp:latest588f3507280e
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
readysettech/sqp-duckdb:latest67a83203ce60
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
reaper99/recipya:v1.2.27f7ec3aeb88c
zlib@1.3.1-r2
1.3.2-r0
1
redash/redash:25.8.000d813437db5
zlib@1:1.2.13.dfsg-1
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
zlib@1:1.2.13.dfsg-1
no fix listed
1
redimp/otterwiki:2778bf30da3da
zlib@1:1.2.13.dfsg-1
no fix listed
1
redis/redisinsight:2.68019fcf774631
zlib@1.3.1-r1
1.3.2-r0
1
redis/redisinsight:3.2.055542a762210
zlib@1.3.1-r2
1.3.2-r0
1
redis/redisinsight:3.485562d67a912
zlib@1.3.1-r2
1.3.2-r0
1
redpandadata/redpanda:latest468bd13a9f2b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
replicated/replicated-sdk:1.0.0-beta.318751b4963250
zlib@1.3.1-r4
1.3.2-r0
1
reportportal/service-auto-analyzer:5.15.5c449b93629a5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
restic/rest-server:0.14.0d2aff06f47eb
zlib@1.3.1-r2
1.3.2-r0
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
zlib@1:1.2.13.dfsg-1
no fix listed
1
rhasspy/wyoming-piper:2.5.27d39aafac409
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
zlib@1:1.2.13.dfsg-1
no fix listed
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
zlib@1:1.2.13.dfsg-1
no fix listed
1
rnwood/smtp4dev:3.6.1912304153668
zlib@1:1.2.13.dfsg-1
no fix listed
1
robustadev/krr:v1.30.0b8d782e568c7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
robustadev/kubewatch:v2.9.00457a51e36e8
zlib@1.3.1-r4
1.3.2-r0
1
rocketadmin/rocketadmin:1.17.710955ef540b9
zlib@1:1.2.13.dfsg-1
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
zlib@1:1.2.13.dfsg-1
no fix listed
1
rocm/k8s-device-plugin:1.31.0.926212c665aab
zlib@1.3.1-r2
1.3.2-r0
1
rommapp/romm:5.2.03512f2ca4557
zlib@1.3.1-r2
1.3.2-r0
1
rommapp/romm:4.4.1b909e95d1aab
zlib@1.3.1-r2
1.3.2-r0
1
rotationalio/beacon:0.2.0f8d8b694515a
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
rotationalio/endeavor:1.3.0ac566baddc06
zlib@1:1.2.13.dfsg-1
no fix listed
1
rotationalio/genoa:1.2.03ab583519215
zlib@1:1.2.13.dfsg-1
no fix listed
1
rotationalio/geoping:1.3.034bcb6fc3cb7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
rotationalio/honu:0.5.069fd30c2e31c
zlib@1:1.2.13.dfsg-1
no fix listed
1
rotationalio/linode-acme-webhook:1.0.0cc7bb030a20f
zlib@1.3.1-r2
1.3.2-r0
1
rotationalio/rotational-api:1.3.0f1a2d05d8fff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
rotationalio/vanity:1.2.0d77350f69b45
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
rqlite/rqlite:9.1.37b992a526eee
zlib@1.3.1-r2
1.3.2-r0
1
rrobetti/ojp:0.1.0-beta1141bd88232b
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
rspamd/rspamd:4.1.4e870599c970d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
rstmdb/rstmdb:lateste5187f2aaace
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.