StackRadar

CVE-2026-27171

Medium

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,460
of 17,790 indexed, latest versions
Container images
2,614
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-27171 affecting package zlib for versions less than 1.3.2-1

Carried by container images the latest versions of 2,460 of 17,790 indexed charts deploy, on 2,614 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.13.dfsg-1, 1:1.3.dfsg-3.1ubuntu2, 1:1.3.dfsg-3.1ubuntu2.1, 1:1.3.dfsg+really1.3.1-1+b1+5 more1:1.3.dfsg-3.1ubuntu2.2, 1:1.3.dfsg+really1.3.1-1+e1, 1:1.3.dfsg+really1.3.1-1ubuntu3.11,706
zlibapk1.3-r2, 1.3.1-r1, 1.3.1-r2, 1.3.1-r4+3 more1.3.2-r0902
zlibrpm1.2.11-lp151.5.3.1, 1.2.13-150500.4.3.1, 1.3.1-1.azl31.2.13-150500.4.6.1, 1.3.1-2.1, 1.3.2-16
OSV records
ALPINE-CVE-2026-27171DEBIAN-CVE-2026-27171CGA-x526-fwrp-6v3cUBUNTU-CVE-2026-27171AZL-77886ECHO-e10b-f259-a98bopenSUSE-SU-2026:10617-1SUSE-SU-2026:0783-1
Also known as
CGA-xjhg-6p5p-42rc, USN-8706-1

Charts affected

2,460 by stars
ChartLatestAffected imagesRadar Score
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
zlib@1:1.3.dfsg-3.1ubuntu2
1:1.3.dfsg-3.1ubuntu2.2

Open the chart page →

2,142
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,849
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,304
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,849
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
zlib@1.3.1-r1
1.3.2-r0

Open the chart page →

9,395
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,684
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

478
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,571
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,849
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27171.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
zlib@1.3.1-r2
1.3.2-r0

Open the chart page →

1,159

Container images carrying it

2,614 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/nginx:1.31:1.31.5:latest:trixie05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
105
library/postgres:18:18.6:18.6-trixie:latest4ef4dbc939d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
69
library/redis:8.10.1:latest298e5b3bc566
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
40
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
23
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
13
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
zlib@1.3.1-r2
1.3.2-r0
13
library/postgres:16f1c3376c26f2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
12
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
zlib@1:1.2.13.dfsg-1
no fix listed
11
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
11
library/mongo:8:8.3.8:latest5211c51171f5
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
11
library/postgres:1767f41722b7a8
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
10
library/rabbitmq:3.13-management:3-managemente582c0bc7766
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
8
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
7
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
7
library/postgres:14156f0b253fd6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
zlib@1:1.2.13.dfsg-1
no fix listed
7
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
7
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
zlib@1:1.2.13.dfsg-1
no fix listed
6
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
zlib@1:1.2.13.dfsg-1
no fix listed
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
zlib@1:1.2.13.dfsg-1
no fix listed
6
curlimages/curl:8.17.0935d9100e9ba
zlib@1.3.1-r2
1.3.2-r0
6
library/postgres:159b1d34adbce1
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
6
library/postgres:18.4a02db8cac496
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
6
library/redis:6:6.2143f7bfc2358
zlib@1:1.2.13.dfsg-1
no fix listed
6
library/ubuntu:latest2260313b31c8
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
1:1.3.dfsg+really1.3.1-1ubuntu3.1
6
library/wordpress:7.1.0-apache:latest5a93c470ae82
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
6
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
zlib@1.3.1-r1
1.3.2-r0
6
valkey/valkey:9.1.1:9.1.1-trixie64e361b630ec
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
zlib@1:1.2.13.dfsg-1
no fix listed
6
quay.io/devtron/postgres:14.91b594392f7cb
zlib@1:1.2.13.dfsg-1
no fix listed
6
alpine/kubectl:1.34.18413f8890d19
zlib@1.3.1-r2
1.3.2-r0
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
zlib@1:1.2.13.dfsg-1
no fix listed
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
zlib@1:1.2.13.dfsg-1
no fix listed
5
keelhq/keel:latest73714afb4443
zlib@1.3.1-r1
1.3.2-r0
5
library/httpd:2.4:2.4.68:latest979c38c2228d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
library/kong:3.9:latest2a8cf3b110cd
zlib@1:1.3.dfsg-3.1ubuntu2.1
1:1.3.dfsg-3.1ubuntu2.2
5
library/memcached:1.6:1.6.4575c93cc91e76
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
library/memcached:1.6.39-alpinec8503d4491ed
zlib@1.3.1-r2
1.3.2-r0
5
library/postgres:122f2a8c2a7d10
zlib@1:1.2.13.dfsg-1
no fix listed
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
zlib@1.3.1-r2
1.3.2-r0
5
library/redis:7.2:7.2-bookworm74566c6910d1
zlib@1:1.2.13.dfsg-1
no fix listed
5
valkey/valkey:9.1.2:latestc123e3715db6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
vaultwarden/server:1.37.2:latest094b5689ed81
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
artifacthub/postgres:latest4fd34fa635cc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
zlib@1:1.2.13.dfsg-1
no fix listed
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
zlib@1:1.2.13.dfsg-1
no fix listed
4
bitnamilegacy/postgresql:16233f361c5819
zlib@1:1.2.13.dfsg-1
no fix listed
4
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
zlib@1:1.2.13.dfsg-1
no fix listed
4
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
zlib@1:1.2.13.dfsg-1
no fix listed
4
cloudflare/cloudflared:2026.3.06b599ca3e974
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.