StackRadar

CVE-2026-42055

Critical

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.065
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
52
of 17,781 indexed, latest versions
Container images
52
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: nginx security, bug fix, and enhancement update

Carried by container images the latest versions of 52 of 17,781 indexed charts deploy, on 52 images.

Affected packageAffected versionsFixed inImages
nginxdeb1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+15 more1.18.0-6ubuntu14.16, 1.22.1-9+deb12u9, 1.24.0-2ubuntu7.13, 1.26.3-3+deb13u725
nginxapk1.26.2-r4, 1.26.3-r0, 1.28.0-r3, 1.28.1-r1+4 more1.26.3-r2, 1.28.3-r414
nginx-mainlineapk1.27.4-r0, 1.27.4-r2, 1.29.8-r11.31.2-r03
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el9, 1:1.22.1-5.module+el9.3.0.z+20438+032561a0+3 more1:1.24.0-3.module+el8.10.0+24503+61c7c092.3, 2:1.20.1-28.el9_8.410
OSV records
ALPINE-CVE-2026-42055CGA-jwcx-pm9x-r4g6DEBIAN-CVE-2026-42055RHSA-2026:36331RHSA-2026:38847UBUNTU-CVE-2026-42055
Also known as
CGA-v6vc-x295-wqcr, RHSA-2026:36618, RHSA-2026:36639, USN-8458-1

Charts affected

52 by stars
ChartLatestAffected imagesRadar Score
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42055.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nginx@1.20.1-1~focal
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42055.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nginx@1.20.1-1~focal
no fix listed

Open the chart page →

28,605

Container images carrying it

52 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
hookiesolutions/webhookie:latest0629694246ba
nginx@1.20.1-1~focal
no fix listed
2
allegroai/clearml:2.0.0-613713ae38f7daf
nginx@1.22.1-9
1.22.1-9+deb12u9
1
andrianrf/backoffice:latest047a7837651e
nginx@1:1.20.1-1.module+el8.8.0+20359+9bd89172.1
1:1.24.0-3.module+el8.10.0+24503+61c7c092.3
1
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
nginx@1.28.2-r1
1.28.3-r4
1
codetogether/codetogether:latest4348c8a38752
nginx@1:1.26.1-2.el9.ngx
2:1.20.1-28.el9_8.4
1
conductoross/conductor:3.31.09fba127693e6
nginx@1.26.3-3+deb13u6
1.26.3-3+deb13u7
1
countly/countly-server:25.05.4e3c238248f99
nginx@1.26.1-2~focal
no fix listed
1
extrim/perlite:1.5.99cb7eb5598b6
nginx@1.26.3-r0
1.26.3-r2
1
fnzv/dump1090:latestb3079b95c336
nginx@1.18.0-6ubuntu14.4
1.18.0-6ubuntu14.16
1
galaxy/galaxy-stable:v18.018e577a626dfd
nginx@1.4.6-1ubuntu3.8ppa1
no fix listed
1
heartexlabs/label-studio:latestaa461572e8f9
nginx@1.28.2-r1
1.28.3-r4
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
nginx@1.18.0-0ubuntu1.3
no fix listed
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
nginx@1.28.0-r3
1.28.3-r4
1
library/nginx:1.28-alpinea8b39bd9cf0f
nginx@1.28.3-r1
1.28.3-r4
1
linuxserver/bookstack:26.05.202605282ebf97852661
nginx@1.28.3-r2
1.28.3-r4
1
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
nginx@1.28.1-r1
1.28.3-r4
1
rocketadmin/rocketadmin:1.17.710955ef540b9
nginx@1.22.1-9+deb12u4
1.22.1-9+deb12u9
1
seafileltd/seafile-mc:9.0.106693911bcc40
nginx@1.18.0-0ubuntu1.4
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
nginx@1.24.0-1~focal
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
nginx@1.18.0-0ubuntu1.3
no fix listed
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nginx@1.18.0-0ubuntu1.2
no fix listed
1
sigp/siren:v3.0.42c219b04758e
nginx@1.22.1-9+deb12u2
1.22.1-9+deb12u9
1
stackstorm/st2web:3.809989a26c8b7
nginx@1.24.0-1~focal
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
nginx@1.26.3-3+deb13u2
1.26.3-3+deb13u7
1
vabene1111/recipes:2.3.50f8d061895e9
nginx@1.28.0-r3
1.28.3-r4
1
xeladock/mysql_dns:latest4baf531453f1
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.16
1
xeladock/nginx2:latestc259a67b1dff
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.16
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
nginx@1.24.0-2ubuntu7.1
1.24.0-2ubuntu7.13
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
nginx@1.20.1-1~focal
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
nginx@1.24.0-2ubuntu7.5
1.24.0-2ubuntu7.13
1
gcr.io/kasten-images/frontend:9.0.54b36f413cabb
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
2:1.20.1-28.el9_8.4
1
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
nginx-mainline@1.27.4-r2
1.31.2-r0
1
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
nginx-mainline@1.27.4-r0
1.31.2-r0
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
nginx@1.28.3-r0
1.28.3-r4
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
nginx@1.22.1-9+deb12u3
1.22.1-9+deb12u9
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nginx@1:1.20.1-13.el9
2:1.20.1-28.el9_8.4
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
nginx@1.26.2-r4
1.26.3-r2
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
nginx@1:1.22.1-5.module+el9.3.0.z+20438+032561a0
2:1.20.1-28.el9_8.4
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nginx@1.18.0-0ubuntu1.2
no fix listed
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
nginx@1.26.2-r4
1.26.3-r2
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
nginx@1.28.3-r1
1.28.3-r4
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
nginx@1.18.0-6ubuntu14.7
1.18.0-6ubuntu14.16
1
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
nginx@1.28.0-r3
1.28.3-r4
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
nginx@1.28.0-r3
1.28.3-r4
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
nginx@1.24.0-2ubuntu7.7
1.24.0-2ubuntu7.13
1
ghcr.io/tarkyaio/tarka-ui:0.4.1b2dfabe13cfe
nginx-mainline@1.29.8-r1
1.31.2-r0
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nginx@1.22.1-9
1.22.1-9+deb12u9
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nginx@1:1.14.1-9.module+el8.0.0+4108+af250afe
1:1.24.0-3.module+el8.10.0+24503+61c7c092.3
1
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
nginx@1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3
2:1.20.1-28.el9_8.4
1
quay.io/maximilianopizarro/custom-rhcl-console:v0.1.270bb0cabd653
nginx@1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3
2:1.20.1-28.el9_8.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.