StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,439
of 17,803 indexed, latest versions
Container images
2,579
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,439 of 17,803 indexed charts deploy, on 2,579 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,675
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0898
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,439 by stars
ChartLatestAffected imagesRadar Score
litlyxlitlyx0.2.04 of 5See more

litlyx litlyx 0.2.0

4 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
litlyx/litlyx-consumer:latest02225e77d316
zlib@1.3.1-r2
1.3.2-r0
litlyx/litlyx-dashboard:lateste64ff2d52385
zlib@1.3.1-r2
1.3.2-r0
litlyx/litlyx-producer:latest10407f36613f
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

7,934
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

7,240
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,781
plexluiscajl1.0.11 of 2See more

plex luiscajl 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1

Open the chart page →

864
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,149
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

1,121
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

6,515
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

5,773
redismagefleet-redis0.1.01 of 1See more

redis magefleet-redis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/redis:7.274566c6910d1
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

1,079
magentomagento3.2.35 of 12See more

magento magento 3.2.3

5 of the 12 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
library/redis:7.274566c6910d1
zlib@1:1.2.13.dfsg-1
no fix listed
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
zlib@1.2.13-150500.4.3.1
1.2.13-150500.4.6.1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
zlib@1.2.13-150500.4.3.1
1.2.13-150500.4.6.1
longhornio/longhorn-ui:v1.10.0e60f36161511
zlib@1.2.13-150500.4.3.1
1.2.13-150500.4.6.1

Open the chart page →

13,685
plane-enterprisemakeplaneOfficialVerified publisher3.7.23 of 13See more

plane-enterprise makeplane 3.7.2

3 of the 13 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
zlib@1.3.1-r1
1.3.2-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
zlib@1.3.1-r1
1.3.2-r0
valkey/valkey:7.2.11-alpine10328d00120d
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

4,973
mcpmcp-chartsVerified publisher0.0.233 of 7See more

mcp mcp-charts 0.0.23

3 of the 7 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1

Open the chart page →

7,053
jellyfinmedia-servarrVerified publisher0.17.11See more

jellyfin media-servarr 0.17.1

1 container image this version deploys carries CVE-2026-27171.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

4,221
mimir-syncmimir-sync3.1.01 of 1See more

mimir-sync mimir-sync 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

1,300
miniapiminiapi1.3.21 of 1See more

miniapi miniapi 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
udhos/miniapi:1.3.28a7042db82ce
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

854
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
zlib@1:1.3.dfsg+really1.3.1-1ubuntu2
no fix listed

Open the chart page →

11,106
mockservermockserverOfficialVerified publisher8.0.01 of 1See more

mockserver mockserver 8.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-8.0.0b8426e0b3c80
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

1,047
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,717
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

13,819
anki-servermt1905022.2.01 of 1See more

anki-server mt190502 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/mt190502/docker-anki-sync-server:25.09.2824245fd5a57
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

382
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/redmine:6.1.204ac44a2595b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

7,617
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,861
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,861
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,907
surveyornatsVerified publisher0.20.91 of 1See more

surveyor nats 0.20.9

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
natsio/nats-surveyor:0.9.9104a3e938b23
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

909
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,667
clowder2ncsaVerified publisher1.9.76 of 12See more

clowder2 ncsa 1.9.7

6 of the 12 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
zlib@1:1.2.13.dfsg-1
no fix listed
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
zlib@1:1.2.13.dfsg-1
no fix listed
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
zlib@1.3.1-r2
1.3.2-r0
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
zlib@1:1.2.13.dfsg-1
no fix listed
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

37,538
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,861
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

14,398
octopuso7studios-octopus-helm-chartsOfficialVerified publisher1.2.33 of 5See more

octopus o7studios-octopus-helm-charts 1.2.3

3 of the 5 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nats:2.11.9-alpine777787bbb4c7
zlib@1.3.1-r2
1.3.2-r0
natsio/nats-box:0.18.0abdc9f9f0120
zlib@1.3.1-r2
1.3.2-r0
natsio/nats-server-config-reloader:0.19.181edf32a3680
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

6,120
oadaoadaVerified publisher5.0.610 of 11See more

oada oada 5.0.6

10 of the 11 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
oada/auth:4.0.0c0d077e79ef4
zlib@1.3.1-r2
1.3.2-r0
oada/http-handler:4.0.0d87efe8ba4b0
zlib@1.3.1-r2
1.3.2-r0
oada/rev-graph-update:4.0.0ebc8343f05ff
zlib@1.3.1-r2
1.3.2-r0
oada/shares:4.0.0c6ffb4e8ed63
zlib@1.3.1-r2
1.3.2-r0
oada/startup:4.0.0fc09495e2f3c
zlib@1.3.1-r2
1.3.2-r0
oada/sync-handler:4.0.0b7a2cfc137cf
zlib@1.3.1-r2
1.3.2-r0
oada/users:4.0.0b6c562fa5b1b
zlib@1.3.1-r2
1.3.2-r0
oada/webhooks:4.0.06590c60de347
zlib@1.3.1-r2
1.3.2-r0
oada/well-known:4.0.07943fde43b19
zlib@1.3.1-r2
1.3.2-r0
oada/write-handler:4.0.08464c7f48aae
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

13,339
dashdotoben01Verified publisher1.5.01 of 1See more

dashdot oben01 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
mauricenino/dashdot:5.9.2236997816917
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,241
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

5,079
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,861
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

14,920
openrouter-botopenrouter-botVerified publisher0.2.01 of 1See more

openrouter-bot openrouter-bot 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
lifailon/openrouter-bot:latestea37e4b6b952
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,059
librechatopenshift1.9.02 of 3See more

librechat openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

5,875
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.41.210 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.2

10 of the 34 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-shipping02602e60edbf
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-mcp654f860148ba
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-accounting74c490f862da
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
zlib@1.3.1-r2
1.3.2-r0
ghcr.io/open-telemetry/demo:3.0.0-frontend9505e349e140
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-agentdf5ee05e23e3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

23,064
openvaultopenvaultVerified publisher0.8.12 of 2See more

openvault openvault 0.8.1

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
zlib@1.3.1-r2
1.3.2-r0
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

6,960
opikopikOfficialVerified publisher2.2.683See more

opik opik 2.2.68

3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.0862d86046bbc
zlib@1.3.1-r2
1.3.2-r0
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
zlib@1.3.1-r2
1.3.2-r0
curlimages/curl:8.12.194e9e444bcba
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

orbitalregorbitalregVerified publisher0.3.01 of 4See more

orbitalreg orbitalreg 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,289
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,735
radarrpanzer1119Verified publisher0.2.21 of 1See more

radarr panzer1119 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/radarr:6.0.4.10291-ls2896c0948b42c14
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

950
sonarrpanzer1119Verified publisher0.2.21 of 1See more

sonarr panzer1119 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sonarr:4.0.16.2944-ls3008b9f2138ec50
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

948
paperless-ngxpaperlessVerified publisher0.4.03 of 3See more

paperless-ngx paperless 0.4.0

3 of the 3 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
zlib@1:1.2.13.dfsg-1
no fix listed
valkey/valkey:9.0.54c64dfeae602
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

8,591
homerpascaliskeVerified publisher3.1.11 of 1See more

homer pascaliske 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/bastienwirtz/homer:v25.11.15c3a0fb561e0
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

292
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

6,897
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

2,086
pbuf-registrypbuf-registry0.4.12 of 2See more

pbuf-registry pbuf-registry 0.4.1

2 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/postgres:18.1-alpine3.2144d837eb4c2e
zlib@1.3.1-r2
1.3.2-r0
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,948

Container images carrying it

2,579 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/zammad/zammad:7.1.3-0014ce435c77651e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/zazukoians/qlever-ui:v0.10.151a7ec1c2de4
zlib@1.3.1-r1
1.3.2-r0
1
ghcr.io/zeroclaw-labs/zeroclaw:v0.1.7497893753e16
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
zlib@1.3.1-r2
1.3.2-r0
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.29a32b89c0c19
zlib@1.3.1-r2
1.3.2-r0
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
zlib@1.3.1-1.azl3
1.3.2-1
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
zlib@1.3.1-r1
1.3.2-r0
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
zlib@1.3.1-r2
1.3.2-r0
1
public.ecr.aws/aktosecurity/redis47200b041382
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
zlib@1.3.1-r2
1.3.2-r0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
zlib@1:1.3.dfsg+really1.3.1-1+b1
1:1.3.dfsg+really1.3.1-1+e1
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
zlib@1:1.3.dfsg+really1.3.1-1+b1
1:1.3.dfsg+really1.3.1-1+e1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
zlib@1.3.1-r1
1.3.2-r0
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
zlib@1.3.1-r1
1.3.2-r0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
zlib@1:1.2.13.dfsg-1
no fix listed
1
public.ecr.aws/truefoundrycloud/timberio/vector:v0.50.05833723de9e4
zlib@1.3.1-r2
1.3.2-r0
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.