StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,431
of 17,792 indexed, latest versions
Container images
2,565
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,431 of 17,792 indexed charts deploy, on 2,565 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+4 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,662
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0897
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,431 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,565 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
airbyte/db:2.3.000cc017f0393
zlib@1.3.1-r2
1.3.2-r0
1
airbyte/manifest-server:7.28.2deec511b51c3
zlib@1:1.2.13.dfsg-1
no fix listed
1
airbyte/pod-sweeper:1.5.198d2c39d512e
zlib@1:1.2.13.dfsg-1
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
zlib@1:1.2.13.dfsg-1
no fix listed
1
akeyless/base:latest759e4289fae8
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
zlib@1.3.1-r2
1.3.2-r0
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
aktosecurity/data-ingestion-service213aded7adc5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
1
alakaganaguathoork/local-business:latest7eb27b0f4a5a
zlib@1.3.1-r2
1.3.2-r0
1
alazidis/stornx:1.1.1602d4f7f090c
zlib@1:1.2.13.dfsg-1
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
zlib@1:1.2.13.dfsg-1
no fix listed
1
alpine/curl:8.12.08943e8c7e8e4
zlib@1.3.1-r2
1.3.2-r0
1
alpine/git:v2.49.1c0280cf95723
zlib@1.3.1-r2
1.3.2-r0
1
alpine/helm105741fa6621
zlib@1.3.1-r1
1.3.2-r0
1
alpine/helm:4.1.0905a068da431
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.36.244ef4942e171
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.31.106dbe6f391eda
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.31.137a319b15cfc9
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.32.47e1e7d5b7a96
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.31.49c4976d47656
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.35.6b7a12c5ddf26
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.30.2cd560fce90f7
zlib@1.3.1-r1
1.3.2-r0
1
alpine/k8s:1.35.5d870622d0040
zlib@1.3.1-r2
1.3.2-r0
1
alpine/k8s:1.28.13e5c0b053fed7
zlib@1.3.1-r1
1.3.2-r0
1
alpine/k8s:1.32.3eec354133193
zlib@1.3.1-r2
1.3.2-r0
1
alpine/kubectl:1.33.32c59a3f0726c
zlib@1.3.1-r2
1.3.2-r0
1
alpine/kubectl:1.35.0862d86046bbc
zlib@1.3.1-r2
1.3.2-r0
1
alpine/kubectl:1.35.3c4a11ae9a1cb
zlib@1.3.1-r2
1.3.2-r0
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
zlib@1.3.1-r2
1.3.2-r0
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
zlib@1.3.1-r2
1.3.2-r0
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
zlib@1:1.2.13.dfsg-1
no fix listed
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
antrea/flow-aggregator:v2.7.0065193e7572f
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
anujdatar/cups:25.07.01685df04a643b
zlib@1:1.2.13.dfsg-1
no fix listed
1
apache/activemq-artemis:2.44.00305c26f19ed
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
1
apache/activemq-artemis:2.37.0bae523439ee3
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2
1
apache/airflow:2.8.4-python3.964e58748b6b9
zlib@1:1.2.13.dfsg-1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
zlib@1:1.2.13.dfsg-1
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.