StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,482
of 17,805 indexed, latest versions
Container images
2,627
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,482 of 17,805 indexed charts deploy, on 2,627 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,715
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0906
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,482 by stars
ChartLatestAffected imagesRadar Score
everest-db-namespaceopeneverestVerified publisher1.16.21 of 1See more

everest-db-namespace openeverest 1.16.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

769
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

887
gcp-pubsub-connectoropenfaas0.0.11 of 1See more

gcp-pubsub-connector openfaas 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

1,162
kafka-connectoropenfaas0.7.151 of 1See more

kafka-connector openfaas 0.7.15

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,165
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,217
pro-builderopenfaas0.6.131 of 2See more

pro-builder openfaas 0.6.13

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,755
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,037
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

912
kruise-gameopenkruise1.1.01 of 1See more

kruise-game openkruise 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

934
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

1,414
openlit-operatoropenlit0.2.21 of 1See more

openlit-operator openlit 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

862
openobserveopenobserve1.0.11 of 6See more

openobserve openobserve 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
natsio/nats-server-config-reloader:0.23.064cb6c858e79
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

3,083
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/redis:7.2.5-alpine6aaf3f5e6bc8
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

3,486
llm-stackopenproject-helm-chartsVerified publisher1.1.02 of 2See more

llm-stack openproject-helm-charts 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
library/python:3.12-slim78387bc3881b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,044
fineractopenshift0.1.13 of 4See more

fineract openshift 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
zlib@1.3.1-r1
1.3.2-r0
library/mariadb:11.4611a2fcc5fa7
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

7,905
sohaopensohaVerified publisher0.1.91 of 2See more

soha opensoha 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,820
terminalsopen-webui0.7.02 of 2See more

terminals open-webui 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/open-webui/terminals:latest5d2fd44366a4
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-webui/terminals-operator:latest6287ce8be502
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,102
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,125
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
replicated/replicated-sdk:1.0.0-beta.318751b4963250
zlib@1.3.1-r4
1.3.2-r0

Open the chart page →

5,661
hiveopstty0.1.92 of 4See more

hive opstty 0.1.9

2 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
alpine/curl:8.12.08943e8c7e8e4
zlib@1.3.1-r2
1.3.2-r0
bitnamilegacy/postgresql:16233f361c5819
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

4,737
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

986
grrosdfir-infrastructureVerified publisher1.0.31 of 5See more

grr osdfir-infrastructure 1.0.3

1 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

11,062
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.029 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

29 of the 40 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
zlib@1:1.2.13.dfsg-1
no fix listed
chromadb/chroma:1.5.7fc8dc8e11fb2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/postgres:17.5-alpine6567bca8d7bc
zlib@1.3.1-r2
1.3.2-r0
library/postgres:17.2-alpine7e5df973a748
zlib@1.3.1-r2
1.3.2-r0
library/redis:7.4.2-alpine02419de7eddf
zlib@1.3.1-r2
1.3.2-r0
yetiplatform/bloomcheck:dev85683ddfccbb
zlib@1.3.1-r2
1.3.2-r0
yetiplatform/yeti:2.9.09bcbe2650a14
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
yetiplatform/yeti-frontend:2.9.0873ef15d267b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
zlib@1.3.1-r2
1.3.2-r0
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

203,308
yetiosdfir-infrastructureVerified publisher1.0.52 of 4See more

yeti osdfir-infrastructure 1.0.5

2 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
yetiplatform/yeti-frontend:latest709064278c7e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

6,789
fluent-bitot-container-kit0.0.31 of 2See more

fluent-bit ot-container-kit 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

929
loki-standaloneot-container-kit1.0.22 of 5See more

loki-standalone ot-container-kit 1.0.2

2 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,667
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

5,426
vm-standaloneot-container-kit0.0.42 of 6See more

vm-standalone ot-container-kit 0.0.4

2 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,506
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,816
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

3,358
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

12,479
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
zlib@1:1.2.13.dfsg-1
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

27,713
parcaparca-rr0.1.01 of 2See more

parca parca-rr 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,405
parcial-1parcial-1-chart1.0.02 of 5See more

parcial-1 parcial-1-chart 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
esteban1930/frontend-1:1.8.0f9078279632c
zlib@1.3.1-r2
1.3.2-r0
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

3,887
istio-cniparticuleio1.1.01 of 1See more

istio-cni particuleio 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
gcr.io/istio-testing/install-cni:latestec6f9ea5757b
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

884
istio-operatorparticuleio1.7.01 of 1See more

istio-operator particuleio 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
gcr.io/istio-testing/operator:latest8d4576f7b98f
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

4,196
clickhousepascaliskeVerified publisher1.0.01 of 1See more

clickhouse pascaliske 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6.70-alpinecd450891db46
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

491
cloudflaredpascaliskeVerified publisher3.0.01 of 1See more

cloudflared pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,071
ctfdpascaliskeVerified publisher2.0.01 of 1See more

ctfd pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,423
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

4,877
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,917
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

960
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,455
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest8672e335dbef
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

4,390
examplepauls-helm-charts0.1.21 of 1See more

example pauls-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
kubeconpauls-helm-charts0.1.01 of 1See more

kubecon pauls-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
stk-fluent-bit-loki-s3paxtecnologia0.2.12 of 6See more

stk-fluent-bit-loki-s3 paxtecnologia 0.2.1

2 of the 6 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/memcached:1.6.39-alpinec8503d4491ed
zlib@1.3.1-r2
1.3.2-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

3,767

Container images carrying it

2,627 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/nmshd/backbone-admin-cli:7.2.1f7d095c04a75
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/nmshd/backbone-admin-ui:7.2.169c9f075d2d9
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-consumer-api:7.2.1b8f0ce01d057
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-database-migrator:7.2.12c0c5e022714
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-event-handler:7.2.1f4d6a2006530
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-housekeeper:7.2.11c1dfe35447f
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/backbone-identity-deletion-jobs:7.2.1da69941fa6b8
zlib@1:1.3.dfsg+really1.3.1-1+dhi2
no fix listed
1
ghcr.io/nmshd/connector:7.4.122f1c515eafa9
zlib@1:1.3.dfsg+really1.3.1-1+dhi3
no fix listed
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaas/gateway:0.27.1382b15393116e
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.