StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,410
of 17,813 indexed, latest versions
Container images
2,591
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,410 of 17,813 indexed charts deploy, on 2,591 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,681
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0904
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,410 by stars
ChartLatestAffected imagesRadar Score
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,334
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

9,518
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,714
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,687
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

493
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,571
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,885
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,187

Container images carrying it

2,591 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/open-telemetry/demo:3.1.0-flagd-ui97a3d37e709f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-emailservicea1f5cebb5240
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-addfd7a4697116
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/open-webui/open-terminal:0.13.0-slimdec44673c865
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/open-webui/terminals:latest5d2fd44366a4
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/open-webui/terminals-operator:latest6287ce8be502
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/paradigmxyz/reth:v2.2.0505fca5e87d6
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/parca-dev/parca:v0.24.23776500fde82
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.