StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,410
of 17,813 indexed, latest versions
Container images
2,591
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,410 of 17,813 indexed charts deploy, on 2,591 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,681
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0904
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,410 by stars
ChartLatestAffected imagesRadar Score
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,334
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

9,518
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,714
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,687
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

493
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,571
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,187

Container images carrying it

2,591 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/mt190502/docker-anki-sync-server:25.09.2824245fd5a57
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/nmshd/backbone-admin-cli:7.2.1f7d095c04a75
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/nmshd/backbone-admin-ui:7.2.169c9f075d2d9
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-consumer-api:7.2.1b8f0ce01d057
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-database-migrator:7.2.12c0c5e022714
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-event-handler:7.2.1f4d6a2006530
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-housekeeper:7.2.11c1dfe35447f
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-identity-deletion-jobs:7.2.1da69941fa6b8
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/connector:7.4.122f1c515eafa9
zlib@1:1.3.dfsg+really1.3.1-1+dhi3
no fix listed
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.