StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,667
of 17,790 indexed, latest versions
Container images
1,598
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,667 of 17,790 indexed charts deploy, on 1,598 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,195
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more392
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,667 by stars
ChartLatestAffected imagesRadar Score
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

14,618
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

9,296
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,229
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,643
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

6,323
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

5,548
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

2,383
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,635
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

13,197
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

3,697
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839

Container images carrying it

1,598 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
intel/trusted-certificate-issuer:0.5.0591a9db4a427
nghttp2@1.40.0-1build1
no fix listed
1
inventree/inventree:1.5.4a946ec09da3e
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
nghttp2@1.40.0-1build1
no fix listed
1
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
nghttp2@1.40.0-1build1
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
nghttp2@1.40.0-1build1
no fix listed
1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
nghttp2@1.40.0-1build1
no fix listed
1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
nghttp2@1.40.0-1build1
no fix listed
1
istio/examples-helloworld-v1:latest328b237e4fb1
nghttp2@1.52.0-1+deb12u1
no fix listed
1
istio/examples-helloworld-v2:latest0a7f02b2c7c9
nghttp2@1.52.0-1+deb12u1
no fix listed
1
istio/install-cni:1.10.32232f365aed6
nghttp2@1.30.0-1ubuntu1
no fix listed
1
istio/install-cni:1.23.6ab34c4740f44
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
istio/install-cni:1.29.0ce27c9ce43c8
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
istio/operator:1.10.3655eefa11c84
nghttp2@1.30.0-1ubuntu1
no fix listed
1
istio/operator:1.12.06cfce8a071b9
nghttp2@1.40.0-1build1
no fix listed
1
istio/operator:1.18.270f9d1fe5fff
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
istio/pilot:1.10.0294ca55bd1cc
nghttp2@1.30.0-1ubuntu1
no fix listed
1
istio/pilot:1.29.0325156535773
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
istio/pilot:1.23.69c3d6a218181
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
istio/pilot:1.17.1ce9d87606701
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
istio/pilot:1.15.2db08d6963975
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
istio/pilot:1.10.3e7e110a421c2
nghttp2@1.30.0-1ubuntu1
no fix listed
1
istio/pilot:1.29.1f8b0e412ac4a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
istio/proxyv2:1.9.687a9db561d2e
nghttp2@1.30.0-1ubuntu1
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
nghttp2@1.30.0-1ubuntu1
no fix listed
1
istio/proxyv2:1.14.1df69c1a7af7c
nghttp2@1.40.0-1build1
no fix listed
1
istio/ztunnel:1.25.005f3972d80a9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ixsystems/truecommand:3.2.019c218455cd2
nghttp2@1.64.0-1.1
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
nghttp2@1.30.0-1ubuntu1
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
nghttp2@1.30.0-1ubuntu1
no fix listed
1
jaedb/iris:latest048cfbf58d57
nghttp2@1.52.0-1+deb12u2
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
nghttp2@1.40.0-1build1
no fix listed
1
jbtronics/part-db1:latest5db71f6db59d
nghttp2@1.52.0-1+deb12u3
no fix listed
1
jedi132000/nextapp:latestdc2a81e92f23
nghttp2@1.40.0-1build1
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
nghttp2@1.64.0-1.1
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
nghttp2@1.64.0-1.1
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
nghttp2@1.52.0-1+deb12u2
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
nghttp2@1.64.0-1.1
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
nghttp2@1.52.0-1+deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
nghttp2@1.52.0-1+deb12u2
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
nghttp2@1.52.0-1+deb12u2
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
nghttp2@1.52.0-1+deb12u1
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
nghttp2@1.52.0-1+deb12u1
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
nghttp2@1.40.0-1ubuntu0.3
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
nghttp2@1.52.0-1+deb12u3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.