StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,855
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

10,418
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,806
resilio-syncgeek-cookbookVerified publisher5.4.21 of 1See more

resilio-sync geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

5,900
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,466
sdtdgeek-cookbookVerified publisher0.3.21 of 1See more

sdtd geek-cookbook 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/reitermarkus/7d2d:main39953b387b61
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

2,523
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

24,355
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

8,955
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

26,996
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,909
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

17,996
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

3,724
mongogengxiankun-charts0.1.01 of 1See more

mongo gengxiankun-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

4,007
rocketmqgengxiankun-charts0.3.01 of 1See more

rocketmq gengxiankun-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/rocketmq:5.3.0434d8398f996
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

4,961
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,266
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.83 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

3 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
no fix listed
library/elasticsearch:7.17.1588c2ec10c7f2
nghttp2@1.40.0-1ubuntu0.2
no fix listed
library/kibana:7.17.150172f1c538e7
nghttp2@1.40.0-1ubuntu0.2
no fix listed

Open the chart page →

34,879
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
nghttp2@1.40.0-1build1
no fix listed
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

16,834
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
nghttp2@1.64.0-1.1+deb13u1
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

12,270
goofy-chartgoofy-chart0.1.01 of 1See more

goofy-chart goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
gosmee-clientgosmee-clientVerified publisher0.1.31 of 1See more

gosmee-client gosmee-client 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/chmouel/gosmee:v0.32.060b8db1f68cc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

246
jaegergpg-dev3.3.32 of 5See more

jaeger gpg-dev 3.3.3

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

19,291
kubernetes-dashboardgpg-dev7.5.01 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

6,075
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
nghttp2@1.52.0-1+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
nghttp2@1.52.0-1+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

47,117
video-analytics-demogpu-operator0.1.92 of 3See more

video-analytics-demo gpu-operator 0.1.9

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
nghttp2@1.40.0-1build1
no fix listed
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

15,780
video-analytics-demo-l4tgpu-operator0.1.31 of 3See more

video-analytics-demo-l4t gpu-operator 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
grafana-cloud-onboardinggrafana0.4.71 of 5See more

grafana-cloud-onboarding grafana 0.4.7

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

4,657
mimir-openshift-experimentalgrafana2.1.02 of 4See more

mimir-openshift-experimental grafana 2.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.12 of 6See more

pyroscope-monitoring grafana 0.1.1

2 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

8,226
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

7,935
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

4,604
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

5,339
routergroundcover1.12.3591 of 7See more

router groundcover 1.12.359

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

6,038
temporalgroundcover1.12.3591 of 2See more

temporal groundcover 1.12.359

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
nghttp2@1.64.0-1.1+e1
1.64.0-1.1+e2

Open the chart page →

2,001
gwangju_2-3gwangju2-30.1.01 of 5See more

gwangju_2-3 gwangju2-3 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fluent/fluent-bit:latestd792375ca8e5
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

6,450
hatchet-hahatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-ha hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,374
hatchet-stackhatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-stack hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,374
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

9,151
web-charthcpark-ktcloudlab0.1.01 of 1See more

web-chart hcpark-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

6,747
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
nghttp2@1.40.0-1ubuntu0.3
no fix listed
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
nghttp2@1.52.0-1
no fix listed

Open the chart page →

23,472
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,287
test-apphellnet0.1.11 of 1See more

test-app hellnet 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
hello-worldhello-world-pponyVerified publisher0.3.01 of 1See more

hello-world hello-world-ppony 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:1.25.49ff236ed47fe
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

5,851
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,655
my_web1helm-chart-by-piyush0.1.01 of 1See more

my_web1 helm-chart-by-piyush 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,693
pageshelm-chart-repos-camden1.0.02 of 3See more

pages helm-chart-repos-camden 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

6,014
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

3,818
ditto-operatorhelm-chartsVerified publisher0.3.01 of 1See more

ditto-operator helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,673
hawkbit-operatorhelm-chartsVerified publisher0.1.41 of 1See more

hawkbit-operator helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ctron/hawkbit-operator:0.1.48fdea8f76499
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

5,791

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jhipster/jhipster-registry:latest7184525acd4d
nghttp2@1.40.0-1ubuntu0.3
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
nghttp2@1.52.0-1+deb12u3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
nghttp2@1.52.0-1+deb12u3
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
nghttp2@1.40.0-1build1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nghttp2@1.40.0-1build1
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kayrosuno/kping:latestf3bd44b29b0d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
nghttp2@1.40.0-1build1
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
nghttp2@1.52.0-1+deb12u3
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
kixote/typemill4e9dff179519
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
kixote/typemill628f79a08cc7
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
nghttp2@1.52.0-1+deb12u1
no fix listed
1
kong/httpbin:latesta6ac46531193
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
nghttp2@1.40.0-1build1
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
kubeflow/model-registry:v0.2.95783f6db428f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
nghttp2@1.30.0-1ubuntu1
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
kuberay/operator:v1.0.04e6ac8a3a2c4
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.3
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
nghttp2@1.52.0-1+deb12u3
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
kuzwolka/aws9:main1ad759b961b1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
laly9999/node-app:1dd0e503913e1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
nghttp2@1.52.0-1+deb12u3
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
nghttp2@1.52.0-1+deb12u3
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
nghttp2@1.52.0-1+deb12u1
no fix listed
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.