StackRadar

CVE-2026-55568

Medium

Advisory

Published 19 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
137
of 17,781 indexed, latest versions
Container images
121
deployed by those charts
Fix available
1 of 1
affected package

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

Carried by container images the latest versions of 137 of 17,781 indexed charts deploy, on 121 images.

Affected packageAffected versionsFixed inImages
guzzlehttp/guzzlecomposer5.3.4, 6.3.0, 6.3.3, 6.5.3+19 more7.12.1121
OSV records
GHSA-wpwq-4j6v-78m3

Charts affected

137 by stars
ChartLatestAffected imagesRadar Score
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
guzzlehttp/guzzle@7.7.0
7.12.1

Open the chart page →

12,813
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
guzzlehttp/guzzle@7.9.2
7.12.1

Open the chart page →

2,293
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,527
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
guzzlehttp/guzzle@6.5.8
7.12.1

Open the chart page →

9,724
orderregistratiecomponentorderregistratiecomponent1.0.01 of 3See more

orderregistratiecomponent orderregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,492
firefly-iiiphntom0.2.101 of 2See more

firefly-iii phntom 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
guzzlehttp/guzzle@7.4.2
7.12.1

Open the chart page →

1,813
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,429
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,510
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

8,725
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,510
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
guzzlehttp/guzzle@7.3.0
7.12.1

Open the chart page →

5,687
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,491
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
guzzlehttp/guzzle@7.4.0
7.12.1

Open the chart page →

2,972
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
guzzlehttp/guzzle@6.3.0
7.12.1

Open the chart page →

2,939
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
guzzlehttp/guzzle@7.7.0
7.12.1

Open the chart page →

2,449
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
guzzlehttp/guzzle@7.9.2
7.12.1

Open the chart page →

9,755
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
guzzlehttp/guzzle@7.4.1
7.12.1

Open the chart page →

2,751
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
guzzlehttp/guzzle@7.9.3
7.12.1

Open the chart page →

6,094
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
guzzlehttp/guzzle@7.11.0
7.12.1

Open the chart page →

4,836
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
guzzlehttp/guzzle@5.3.4
7.12.1

Open the chart page →

1,136
cachetsergiotocaliniVerified publisher1.0.01 of 1See more

cachet sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
guzzlehttp/guzzle@6.3.3
7.12.1

Open the chart page →

1,896
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
guzzlehttp/guzzle@6.5.8
7.12.1

Open the chart page →

2,825
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
guzzlehttp/guzzle@7.8.1
7.12.1

Open the chart page →

2,038
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,480
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

3,993
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
guzzlehttp/guzzle@7.9.2
7.12.1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
guzzlehttp/guzzle@7.8.1
7.12.1

Open the chart page →

10,006
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,429
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
guzzlehttp/guzzle@6.5.8
7.12.1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
guzzlehttp/guzzle@7.2.0
7.12.1

Open the chart page →

2,132
tool-quickstatementswbstack0.4.01 of 1See more

tool-quickstatements wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
guzzlehttp/guzzle@7.4.0
7.12.1

Open the chart page →

1,698
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
guzzlehttp/guzzle@6.5.5
7.12.1

Open the chart page →

7,552
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-55568.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
guzzlehttp/guzzle@7.10.0
7.12.1

Open the chart page →

1,042

Container images carrying it

121 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
guzzlehttp/guzzle@6.5.8
7.12.1
5
cachethq/docker:2.3.15a61ff0f67ea7
guzzlehttp/guzzle@6.3.3
7.12.1
4
buddy/repman:1.4.0097c897f8b54
guzzlehttp/guzzle@6.5.5
7.12.1
3
mautic/mautic:2.13-apachea954c5868d76
guzzlehttp/guzzle@6.3.0
7.12.1
3
wallabag/wallabag:2.6.144a527e027e0d
guzzlehttp/guzzle@5.3.4
7.12.1
3
fireflyiii/core:version-6.5.9fe4ecec4c2ba
guzzlehttp/guzzle@7.10.0
7.12.1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
guzzlehttp/guzzle@7.10.0
7.12.1
2
ujamii/prometheus-sentry-exporter:0.5.06243197349e1
guzzlehttp/guzzle@6.3.3
7.12.1
2
vdiogov/glpi-conteiner:latest6945f84f0058
guzzlehttp/guzzle@7.5.0
7.12.1
2
akaunting/akaunting:3.0.1552811b36ec3a
guzzlehttp/guzzle@7.7.0
7.12.1
1
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
guzzlehttp/guzzle@7.10.0
7.12.1
1
anonaddy/anonaddy:0.12.3957a95565166
guzzlehttp/guzzle@7.4.5
7.12.1
1
castopod/castopod:1.12.101fd37280cbb2
guzzlehttp/guzzle@7.9.2
7.12.1
1
castopod/castopod:1.15.54e4f0440520f
guzzlehttp/guzzle@7.10.0
7.12.1
1
cloudtooling/moodle:5.2.3f4f04e0fc401
guzzlehttp/guzzle@7.10.0
7.12.1
1
conduction/agendaservice-php:latest9cfeeb6c7c20
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/balance-registration-php:devc36094a41369
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/betaalservice-php:latestece1ab544c57
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/cgrc-php:dev25415534d245
guzzlehttp/guzzle@6.5.3
7.12.1
1
conduction/checkin-component-php:dev3423845692c1
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/conduction-ui-php:dev2744565516e8
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/docparser-php:devb6f95c8ead7d
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/kvk-php:dev8f177f9f8a7b
guzzlehttp/guzzle@6.5.5
7.12.1
1
conduction/pan-php:dev24f03c57568f
guzzlehttp/guzzle@6.5.5
7.12.1
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
guzzlehttp/guzzle@7.10.0
7.12.1
1
daledavies/jump:v1.4.10a0c8ad93902
guzzlehttp/guzzle@7.8.1
7.12.1
1
digitalist/matomo:5.12.0bc4aeeaea769
guzzlehttp/guzzle@7.10.0
7.12.1
1
espocrm/espocrm:9.3.101b5a24504ed9
guzzlehttp/guzzle@7.10.0
7.12.1
1
fireflyiii/core:version-5.6.142f4283bd0cf7
guzzlehttp/guzzle@7.4.1
7.12.1
1
fossology/fossology:4.2.18bd1f22ba7bb
guzzlehttp/guzzle@7.5.0
7.12.1
1
invoiceninja/invoiceninja:5.6.241437916dee01
guzzlehttp/guzzle@7.7.0
7.12.1
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
guzzlehttp/guzzle@7.9.3
7.12.1
1
jordan/icinga2:latestf75025fe8ea8
guzzlehttp/guzzle@6.5.5
7.12.1
1
leantime/leantime:3.3.3ad4bfb0699d3
guzzlehttp/guzzle@7.9.2
7.12.1
1
library/drupal:8-apache8a1a3ee83899
guzzlehttp/guzzle@6.5.4
7.12.1
1
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
guzzlehttp/guzzle@7.8.1
7.12.1
1
library/monica:3.7.0-apacheceb1ba4196ab
guzzlehttp/guzzle@7.4.1
7.12.1
1
library/nextcloud:31.0.6-apache588609d76b21
guzzlehttp/guzzle@7.9.2
7.12.1
1
library/nextcloud:17.0.0-apache96104cb965fc
guzzlehttp/guzzle@6.3.3
7.12.1
1
library/nextcloud:31.0.10-apacheb7faa1653c39
guzzlehttp/guzzle@7.9.2
7.12.1
1
librenms/librenms:24.11.00920bc9117a8
guzzlehttp/guzzle@7.9.2
7.12.1
1
librenms/librenms:22.4.14f1f3d667cc7
guzzlehttp/guzzle@7.4.1
7.12.1
1
linkstackorg/linkstack:latest1c8b05399ee4
guzzlehttp/guzzle@7.10.0
7.12.1
1
linuxserver/bookstack:26.05.202605282ebf97852661
guzzlehttp/guzzle@7.10.5
7.12.1
1
linuxserver/grocy:version-v3.1.3291296e66c2a
guzzlehttp/guzzle@7.4.0
7.12.1
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
guzzlehttp/guzzle@7.7.0
7.12.1
1
linuxserver/heimdall:2.6.371597f4461e4
guzzlehttp/guzzle@7.8.1
7.12.1
1
lycheeorg/lychee-laravel:v4.3.0308c0e6231da
guzzlehttp/guzzle@7.3.0
7.12.1
1
martinhelmich/typo3:12.4c83a4f3fd7ae
guzzlehttp/guzzle@7.10.0
7.12.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.