StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

42,345
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,516
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,454
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,201
apishiftapishiftVerified publisher0.3.02 of 4See more

apishift apishift 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

2,947
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

6,227
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

19,784
app-mobilityappmo0.1.02 of 5See more

app-mobility appmo 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,520
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,605
aceappscodeVerified publisher2026.9.111 of 2See more

ace appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,907
ace-installerappscodeVerified publisher2026.9.111 of 2See more

ace-installer appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,239
ace-installer-certifiedappscodeVerified publisher2026.9.111 of 2See more

ace-installer-certified appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,239
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,605
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

640
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

640
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,056
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

4,002
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

15,707
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

17,110
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,404
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

912
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,605
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,043
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,568
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

37,184
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,310
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
no fix listed

Open the chart page →

4,899
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,902
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,521
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

7,338
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,819
arlas-aiasarlas-stackVerified publisher28.8.07 of 22See more

arlas-aias arlas-stack 28.8.0

7 of the 22 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

40,411
titilerarlas-stackVerified publisher28.8.01 of 1See more

titiler arlas-stack 28.8.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,423
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

23,407
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

3,568
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
no fix listed
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

22,677
assemblylineassemblylineVerified publisher7.4.193 of 12See more

assemblyline assemblyline 7.4.19

3 of the 12 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable19c914f21a41d7
nghttp2@1.52.0-1+deb12u3
no fix listed
cccs/assemblyline-socketio:4.7.4.stable19caf40394bd17
nghttp2@1.52.0-1+deb12u3
no fix listed
cccs/assemblyline-ui:4.7.4.stable190426ed7884a2
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

12,092
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

14,725
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

9,407
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,799
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

10,101
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

18,331
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

8,042
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

7,982
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

5,368
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
no fix listed
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

42,460
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
no fix listed
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

13,986
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

31,807
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

8,555
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

6,948

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
firefart/requesttracker:5.0.40d6249906d8c
nghttp2@1.52.0-1
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
nghttp2@1.40.0-1ubuntu0.3
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
nghttp2@1.52.0-1+deb12u2
no fix listed
1
fiware/mintaka:0.7.092a3c5cf43c0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
fiware/mintaka:latestefc6793388cc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
fiware/orion-ld:1.10.03c490a746f65
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
flanksource/batch-runner:v1.0.44689687a7cf95
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
flashcatcloud/categraf:latest42e6ab16472e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
fluent/fluent-bit:4.2.6a52221a2a3eb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
fluent/fluent-bit:5.1.1a941bdd5ca55
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
fluent/fluent-bit:4.0.4ca08b7d2df5b
nghttp2@1.52.0-1+deb12u2
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
nghttp2@1.52.0-1+deb12u2
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
nghttp2@1.40.0-1build1
no fix listed
1
fosrl/pangolin:latest83a55f933b4d
nghttp2@1.52.0-1+deb12u3
no fix listed
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
nghttp2@1.30.0-1ubuntu1
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
nghttp2@1.30.0-1ubuntu1
no fix listed
1
frankescobar/allure-docker-service:latestdc171ec796d5
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
freikin/dawarich:1.14.511826c67e4b1
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
galaxy/cloudman-server:lateste5c265fe9fcd
nghttp2@1.40.0-1build1
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
nghttp2@1.52.0-1+deb12u2
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
nghttp2@1.43.0-1ubuntu0.3
1.43.0-1ubuntu0.4
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
nghttp2@1.30.0-1ubuntu1
no fix listed
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
nghttp2@1.40.0-1build1
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
nghttp2@1.40.0-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
nghttp2@1.40.0-1build1
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
nghttp2@1.40.0-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
nghttp2@1.40.0-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
nghttp2@1.40.0-1build1
no fix listed
1
gethue/hue:4.11.011b649636e68
nghttp2@1.40.0-1build1
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
nghttp2@1.30.0-1ubuntu1
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
getsentry/relay:24.10.0ba7bf9163219
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
nghttp2@1.52.0-1+deb12u3
no fix listed
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
nghttp2@1.40.0-1build1
no fix listed
1
glpi/glpi:latest4b681082a79e
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
gocd/gocd-agent-wolfi:v26.1.0753b9f696f45
nghttp2@1.69.0-r0
1.70.0-r0
1
gocd/gocd-server:v26.1.0720d1012b93f
nghttp2@1.69.0-r0
1.70.0-r0
1
gotenberg/gotenberg:8.30206a6c708fc6
nghttp2@1.64.0-1.1
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
nghttp2@1.30.0-1ubuntu1
no fix listed
1
gradiant/open5gs-dbctl:0.10.3332031245fce
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
graylog/graylog:6.1.1019de1aff48c2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
grpl/grapple-cli:0.2.127c00aafee6629
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
guacamole/guacamole:1.5.50f62f6d17ab3
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
gulacedia/web-dvwa-new:v367b467d961ca
nghttp2@1.52.0-1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.