StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,482
of 17,805 indexed, latest versions
Container images
2,627
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,482 of 17,805 indexed charts deploy, on 2,627 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,715
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0906
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,482 by stars
ChartLatestAffected imagesRadar Score
everest-db-namespaceopeneverestVerified publisher1.16.21 of 1See more

everest-db-namespace openeverest 1.16.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

769
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

887
gcp-pubsub-connectoropenfaas0.0.11 of 1See more

gcp-pubsub-connector openfaas 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

1,162
kafka-connectoropenfaas0.7.151 of 1See more

kafka-connector openfaas 0.7.15

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,165
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,217
pro-builderopenfaas0.6.131 of 2See more

pro-builder openfaas 0.6.13

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,755
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,037
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

912
kruise-gameopenkruise1.1.01 of 1See more

kruise-game openkruise 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

934
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

1,414
openlit-operatoropenlit0.2.21 of 1See more

openlit-operator openlit 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

862
openobserveopenobserve1.0.11 of 6See more

openobserve openobserve 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
natsio/nats-server-config-reloader:0.23.064cb6c858e79
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

3,083
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/redis:7.2.5-alpine6aaf3f5e6bc8
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

3,486
llm-stackopenproject-helm-chartsVerified publisher1.1.02 of 2See more

llm-stack openproject-helm-charts 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
library/python:3.12-slim78387bc3881b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,044
fineractopenshift0.1.13 of 4See more

fineract openshift 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
zlib@1.3.1-r1
1.3.2-r0
library/mariadb:11.4611a2fcc5fa7
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

7,905
sohaopensohaVerified publisher0.1.91 of 2See more

soha opensoha 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,820
terminalsopen-webui0.7.02 of 2See more

terminals open-webui 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/open-webui/terminals:latest5d2fd44366a4
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-webui/terminals-operator:latest6287ce8be502
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,102
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,125
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
replicated/replicated-sdk:1.0.0-beta.318751b4963250
zlib@1.3.1-r4
1.3.2-r0

Open the chart page →

5,661
hiveopstty0.1.92 of 4See more

hive opstty 0.1.9

2 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
alpine/curl:8.12.08943e8c7e8e4
zlib@1.3.1-r2
1.3.2-r0
bitnamilegacy/postgresql:16233f361c5819
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

4,737
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

986
grrosdfir-infrastructureVerified publisher1.0.31 of 5See more

grr osdfir-infrastructure 1.0.3

1 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

11,062
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.029 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

29 of the 40 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
zlib@1:1.2.13.dfsg-1
no fix listed
chromadb/chroma:1.5.7fc8dc8e11fb2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/postgres:17.5-alpine6567bca8d7bc
zlib@1.3.1-r2
1.3.2-r0
library/postgres:17.2-alpine7e5df973a748
zlib@1.3.1-r2
1.3.2-r0
library/redis:7.4.2-alpine02419de7eddf
zlib@1.3.1-r2
1.3.2-r0
yetiplatform/bloomcheck:dev85683ddfccbb
zlib@1.3.1-r2
1.3.2-r0
yetiplatform/yeti:2.9.09bcbe2650a14
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
yetiplatform/yeti-frontend:2.9.0873ef15d267b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
zlib@1.3.1-r2
1.3.2-r0
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

203,308
yetiosdfir-infrastructureVerified publisher1.0.52 of 4See more

yeti osdfir-infrastructure 1.0.5

2 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
yetiplatform/yeti-frontend:latest709064278c7e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

6,789
fluent-bitot-container-kit0.0.31 of 2See more

fluent-bit ot-container-kit 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

929
loki-standaloneot-container-kit1.0.22 of 5See more

loki-standalone ot-container-kit 1.0.2

2 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,667
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

5,426
vm-standaloneot-container-kit0.0.42 of 6See more

vm-standalone ot-container-kit 0.0.4

2 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,506
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,816
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

3,358
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

12,479
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
zlib@1:1.2.13.dfsg-1
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

27,713
parcaparca-rr0.1.01 of 2See more

parca parca-rr 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,405
parcial-1parcial-1-chart1.0.02 of 5See more

parcial-1 parcial-1-chart 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
esteban1930/frontend-1:1.8.0f9078279632c
zlib@1.3.1-r2
1.3.2-r0
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

3,887
istio-cniparticuleio1.1.01 of 1See more

istio-cni particuleio 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
gcr.io/istio-testing/install-cni:latestec6f9ea5757b
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

884
istio-operatorparticuleio1.7.01 of 1See more

istio-operator particuleio 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
gcr.io/istio-testing/operator:latest8d4576f7b98f
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

4,196
clickhousepascaliskeVerified publisher1.0.01 of 1See more

clickhouse pascaliske 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6.70-alpinecd450891db46
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

491
cloudflaredpascaliskeVerified publisher3.0.01 of 1See more

cloudflared pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,071
ctfdpascaliskeVerified publisher2.0.01 of 1See more

ctfd pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,423
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

4,877
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,917
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

960
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,455
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest8672e335dbef
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

4,390
examplepauls-helm-charts0.1.21 of 1See more

example pauls-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
kubeconpauls-helm-charts0.1.01 of 1See more

kubecon pauls-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
stk-fluent-bit-loki-s3paxtecnologia0.2.12 of 6See more

stk-fluent-bit-loki-s3 paxtecnologia 0.2.1

2 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/memcached:1.6.39-alpinec8503d4491ed
zlib@1.3.1-r2
1.3.2-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

3,767

Container images carrying it

2,627 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/madeddie/opds-aggregator:latest60c56021c552
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mattn/picoclaw:latest517556c8b144
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mcp-hangar/mcp-hangar:2.21.0ee409f91176c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mt190502/docker-anki-sync-server:25.09.2824245fd5a57
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.