StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,460
of 17,790 indexed, latest versions
Container images
2,614
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,460 of 17,790 indexed charts deploy, on 2,614 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,706
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0902
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,460 by stars
ChartLatestAffected imagesRadar Score
wgerwgerOfficialVerified publisher1.0.05 of 8See more

wger wger 1.0.0

5 of the 8 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/postgres:15.186eb0add3b77c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/redis:8.8.0234c902a2db4
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
wger/server:2.6997ead43aabd
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

8,634
windmillwindmill4.0.2641 of 3See more

windmill windmill 4.0.264

1 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,649
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

923
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

4,017
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

4,651
zeroclawzeroclawVerified publisher0.2.11 of 2See more

zeroclaw zeroclaw 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/zeroclaw-labs/zeroclaw:v0.1.7497893753e16
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

794
paperless-ngxadnoctemVerified publisher0.4.22 of 5See more

paperless-ngx adnoctem 0.4.2

2 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

19,828
agentareaagentareaVerified publisher0.0.187 of 16See more

agentarea agentarea 0.0.18

7 of the 16 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
agentarea/agentarea-api:latest9e15e16fa758
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
agentarea/agentarea-mcp-runner:latestd3c209a5d531
zlib@1:1.2.13.dfsg-1
no fix listed
agentarea/agentarea-worker:latest1e5cb68ee77a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
oryd/kratos:v1.3.1fe2428f103a6
zlib@1.3.1-r1
1.3.2-r0
temporalio/auto-setup:1.29.15b3502a3b685
zlib@1.3.1-r2
1.3.2-r0
temporalio/ui:2.39.0b768f87f18b5
zlib@1.3.1-r2
1.3.2-r0
valkey/valkey:9.0.1546304417fea
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

15,049
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.231 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.23

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

2,411
icat-k8salba-helm-chartsVerified publisher1.1.02 of 4See more

icat-k8s alba-helm-charts 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
curlimages/curl:8.18.0d94d07ba9e7d
zlib@1.3.1-r2
1.3.2-r0
payara/micro:7.2026.2-jdk25fb44b8ce1cb2
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

3,746
cloudflaredalekcVerified publisher1.8.11 of 1See more

cloudflared alekc 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.9.1b269e8abd07a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

336
jellyfinalekcVerified publisher0.9.01 of 1See more

jellyfin alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,626
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.02 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

12,092
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

5,971
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

2,387
upcloud-csiankra-chartsVerified publisher0.4.01 of 8See more

upcloud-csi ankra-charts 0.4.0

1 of the 8 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

14,969
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

3,395
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
zlib@1:1.2.13.dfsg-1
no fix listed
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

22,304
antreaantreaVerified publisher2.7.02 of 2See more

antrea antrea 2.7.0

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

3,539
scannerappscodeVerified publisher2026.1.152 of 3See more

scanner appscode 2026.1.15

2 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
zlib@1.3.1-r2
1.3.2-r0
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

5,315
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

5,249
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

1,736
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,327
astradnsastradnsVerified publisher0.2.91 of 2See more

astradns astradns 0.2.9

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,649
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,702
aramid-indexerbiatec-repoVerified publisher3.9.04 of 5See more

aramid-indexer biatec-repo 3.9.0

4 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1

Open the chart page →

13,544
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

5,117
self-hostbitwarden2.4.11 of 11See more

self-host bitwarden 2.4.1

1 of the 11 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

5,269
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,919
plexbrandan-schmitz-helm-chartsVerified publisher1.5.11 of 1See more

plex brandan-schmitz-helm-charts 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
linuxserver/plex:1.43.22785a6ad64d3
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

1,163
brightdata-exporterbrightdata-chartsVerified publisher0.2.171 of 1See more

brightdata-exporter brightdata-charts 0.2.17

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/danielgines/brightdata-exporter:0.2.176920d17cf6ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,306
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,541
static-httpserverbyjgVerified publisher0.2.01 of 1See more

static-httpserver byjg 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
byjg/static-httpserver:latest562cc8b9c40b
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

677
nacosbytectl0.1.61 of 1See more

nacos bytectl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1

Open the chart page →

1,827
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,490
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,490
pgcagriekinVerified publisher2.1.01 of 2See more

pg cagriekin 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,309
pgvectorcagriekinVerified publisher2.1.02 of 3See more

pgvector cagriekin 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

4,056
carbone-eecarboneOfficialVerified publisher1.0.61 of 1See more

carbone-ee carbone 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
carbone/carbone-ee:full-5.11.0518172cbad49
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,641
cbioportalcbioportalOfficialVerified publisher1.1.01 of 1See more

cbioportal cbioportal 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

3,745
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

1,810
finops-stackcert-managerVerified publisher0.0.51 of 12See more

finops-stack cert-manager 0.0.5

1 of the 12 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

12,611
cert-vaultcert-vaultOfficialVerified publisher2.12.06 of 7See more

cert-vault cert-vault 2.12.0

6 of the 7 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
zlib@1:1.2.13.dfsg-1
no fix listed
library/postgres:1767f41722b7a8
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

16,056
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,383
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,144
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
zlib@1:1.2.13.dfsg-1
no fix listed
proxysql/proxysql:3.0.110e95d1b7cc32
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

10,931
squestchristianhuthVerified publisher6.6.73 of 4See more

squest christianhuth 6.6.7

3 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

10,039
typo3christianhuthVerified publisher7.7.12 of 2See more

typo3 christianhuth 7.7.1

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
zlib@1:1.2.13.dfsg-1
no fix listed
martinhelmich/typo3:12.4c83a4f3fd7ae
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

8,597
chromadbchromadb-helmVerified publisher0.2.21 of 1See more

chromadb chromadb-helm 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.3cfd193653bd6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,454
challengerchronicleVerified publisher0.1.11 of 1See more

challenger chronicle 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

977

Container images carrying it

2,614 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.3:latestecacd9fd0c66
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.5f69554198005
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/dmunozv04/isponsorblocktv:v2.9.05b8cfa805cb6
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/dragoangel/mcrouter:v2026.06.29.0042afcffe67d0
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/drakkan/sftpgo:v2.7.46cb60f08fede
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/dysnix/docker-tiny:0.0.16b8e02430649
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/elastiflow/mermin:v0.4.1205053c8a3e2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/element-hq/hydrogen-web:v0.5.12d15d14b201a
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/element-hq/matrix-authentication-service:1.24.052c18ffcc940
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/esomore/bitcoin-prometheus-exporter:masterded173632986
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/ethpandaops/dispatchoor-web:latest18e30413dac2
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/feresberbeche/alertigate:1.2.1628d49e0e01b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/ferriskey/ferriskey-api:0.7.228b6adba10f8
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/firecrawl/firecrawl:2.11.340529f38bab2c3
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
zlib@1.3.1-r2
1.3.2-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.