StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

42,345
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,516
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,454
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,201
apishiftapishiftVerified publisher0.3.02 of 4See more

apishift apishift 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

2,947
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

6,227
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

19,784
app-mobilityappmo0.1.02 of 5See more

app-mobility appmo 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,520
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,605
aceappscodeVerified publisher2026.9.111 of 2See more

ace appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,907
ace-installerappscodeVerified publisher2026.9.111 of 2See more

ace-installer appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,239
ace-installer-certifiedappscodeVerified publisher2026.9.111 of 2See more

ace-installer-certified appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,239
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,605
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

640
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

640
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,056
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

4,002
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

15,707
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

17,110
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,404
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

912
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,605
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,043
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,568
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

37,184
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,310
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
no fix listed

Open the chart page →

4,899
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,902
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,521
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

7,338
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,819
arlas-aiasarlas-stackVerified publisher28.8.07 of 22See more

arlas-aias arlas-stack 28.8.0

7 of the 22 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

40,411
titilerarlas-stackVerified publisher28.8.01 of 1See more

titiler arlas-stack 28.8.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,423
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

23,407
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

3,568
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
no fix listed
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

22,677
assemblylineassemblylineVerified publisher7.4.193 of 12See more

assemblyline assemblyline 7.4.19

3 of the 12 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable19c914f21a41d7
nghttp2@1.52.0-1+deb12u3
no fix listed
cccs/assemblyline-socketio:4.7.4.stable19caf40394bd17
nghttp2@1.52.0-1+deb12u3
no fix listed
cccs/assemblyline-ui:4.7.4.stable190426ed7884a2
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

12,092
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

14,725
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

9,407
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,799
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

10,101
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

18,331
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

8,042
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

7,982
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

5,368
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
no fix listed
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

42,460
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
no fix listed
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

13,986
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

31,807
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

8,555
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

6,948

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jhipster/jhipster-registry:latest7184525acd4d
nghttp2@1.40.0-1ubuntu0.3
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
nghttp2@1.52.0-1+deb12u3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
nghttp2@1.52.0-1+deb12u3
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
nghttp2@1.40.0-1build1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nghttp2@1.40.0-1build1
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kayrosuno/kping:latestf3bd44b29b0d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
nghttp2@1.40.0-1build1
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
nghttp2@1.52.0-1+deb12u3
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
kixote/typemill4e9dff179519
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
kixote/typemill628f79a08cc7
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
nghttp2@1.52.0-1+deb12u1
no fix listed
1
kong/httpbin:latesta6ac46531193
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
nghttp2@1.40.0-1build1
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
kubeflow/model-registry:v0.2.95783f6db428f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
nghttp2@1.30.0-1ubuntu1
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
kuberay/operator:v1.0.04e6ac8a3a2c4
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.3
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
nghttp2@1.52.0-1+deb12u3
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
kuzwolka/aws9:main1ad759b961b1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
laly9999/node-app:1dd0e503913e1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
nghttp2@1.52.0-1+deb12u3
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
nghttp2@1.52.0-1+deb12u3
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
nghttp2@1.52.0-1+deb12u1
no fix listed
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.