StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
eoloplanthttpd-eoloplant0.1.04 of 7See more

eoloplant httpd-eoloplant 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

32,336
nexus3huangchengwu-helm-chart0.1.01 of 1See more

nexus3 huangchengwu-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sonatype/nexus3:3.53.04bd975493104
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,462
prometheushuangchengwu-helm-chart0.1.02 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
apache/skywalking-ui:9.2.0295f1dc87d98
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

16,482
skywalking-v1huangchengwu-helm-chart0.1.02 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
nghttp2@1.40.0-1build1
no fix listed
apache/skywalking-ui:8.9.180530f0308a5
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

20,727
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

9,038
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,749
nginx-charthyomin-nginx0.1.01 of 1See more

nginx-chart hyomin-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
hyperglance-helmhyperglance-helmVerified publisher10.0.53 of 6See more

hyperglance-helm hyperglance-helm 10.0.5

3 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hyperglance/init:wildfly467ad8491bc3
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
hyperglance/init:postgres9fd5faf1fe80
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
hyperglance/init:apacheb2f8c6d52623
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

11,171
nginx-charthyun-nginx0.1.01 of 1See more

nginx-chart hyun-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

7,184
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

7,902
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,770
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

57,728
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.3
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,460
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

12,632
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2fac502149c40
nghttp2@1.52.0-1+deb12u2
no fix listed
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
nghttp2@1.33.0-1.el8
0:1.33.0-6.el8_10.3

Open the chart page →

11,975
nextjsicoretechVerified publisher1.2.01 of 1See more

nextjs icoretech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
monitoring-stackict-platformVerified publisher0.4.01 of 13See more

monitoring-stack ict-platform 0.4.0

1 of the 13 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

9,597
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

3,181
eoloserverihuertas2021-vmartinp2021-helm0.1.03 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

27,812
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

9,032
ikigaiikigai-chartVerified publisher0.0.94 of 58See more

ikigai ikigai-chart 0.0.9

4 of the 58 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
no fix listed
kuberay/operator:v1.0.04e6ac8a3a2c4
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.3
library/zookeeper:3.8-temurin55d1e5b2e601
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

37,844
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

11,838
web-chartimcherry57780.1.01 of 1See more

web-chart imcherry5778 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
onechartimioVerified publisher0.76.01 of 1See more

onechart imio 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

16,226
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

5,360
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,954
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
nghttp2@1.52.0-1+deb12u2
no fix listed
library/influxdb:1.12.3-datab0f9fc41ed79
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,736
influxdbinfluxdb20.1.01 of 1See more

influxdb influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/influxdb:latestf75e48af0598
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,237
op-stackinfradao0.0.11 of 1See more

op-stack infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

10,542
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

7,457
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

18,137
kesintelVerified publisher0.8.31 of 1See more

kes intel 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
minio/kes:v0.22.255f3aef5803e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

3,570
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

5,996
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

16,558
interbtc-parachaininterlay0.4.131 of 1See more

interbtc-parachain interlay 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

3,195
polkabtc-parachaininterlay0.2.411 of 4See more

polkabtc-parachain interlay 0.2.41

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

3,937
inventreeinventreeOfficialVerified publisher0.4.282 of 2See more

inventree inventree 0.4.28

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
nghttp2@1.64.0-1.1+deb13u1
no fix listed
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,757
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

5,570
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

5,570
ztunnelistio-ztunnelVerified publisher1.25.01 of 1See more

ztunnel istio-ztunnel 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/ztunnel:1.25.005f3972d80a9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,497
daveit-at-mOfficialVerified publisher0.2.158 of 11See more

dave it-at-m 0.2.15

8 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

15,245
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,965
wjh-rechnerit-at-mOfficialVerified publisher1.0.41 of 1See more

wjh-rechner it-at-m 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_8.2

Open the chart page →

3,487
zammad-ldap-syncit-at-mVerified publisher0.6.51 of 1See more

zammad-ldap-sync it-at-m 0.6.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

1,364
dynamic-ip-loadbalancer-controlleritsmethemojoVerified publisher0.1.01 of 1See more

dynamic-ip-loadbalancer-controller itsmethemojo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,692
tekton-git-listeneritsmethemojoVerified publisher0.1.11 of 1See more

tekton-git-listener itsmethemojo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/buildpack-deps:scmac978b783657
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,178
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nghttp2@1.52.0-1+deb12u2
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nghttp2@1.52.0-1+deb12u2
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nghttp2@1.52.0-1+deb12u2
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nghttp2@1.52.0-1+deb12u2
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nghttp2@1.52.0-1+deb12u2
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

45,392

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jhipster/jhipster-registry:latest7184525acd4d
nghttp2@1.40.0-1ubuntu0.3
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
nghttp2@1.52.0-1+deb12u3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
nghttp2@1.52.0-1+deb12u3
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
nghttp2@1.40.0-1build1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nghttp2@1.40.0-1build1
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
kayrosuno/kping:latestf3bd44b29b0d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
nghttp2@1.40.0-1build1
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
nghttp2@1.52.0-1+deb12u3
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
kixote/typemill4e9dff179519
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
kixote/typemill628f79a08cc7
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
nghttp2@1.52.0-1+deb12u1
no fix listed
1
kong/httpbin:latesta6ac46531193
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
nghttp2@1.40.0-1build1
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
kubeflow/model-registry:v0.2.95783f6db428f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
nghttp2@1.30.0-1ubuntu1
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
kuberay/operator:v1.0.04e6ac8a3a2c4
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.3
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
nghttp2@1.52.0-1+deb12u3
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
kuzwolka/aws9:main1ad759b961b1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
nghttp2@1.52.0-1+deb12u2
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
laly9999/node-app:1dd0e503913e1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
nghttp2@1.52.0-1+deb12u3
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
nghttp2@1.52.0-1+deb12u2
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
nghttp2@1.52.0-1+deb12u3
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
nghttp2@1.52.0-1+deb12u1
no fix listed
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.