StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

7,883
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,728
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

8,139
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

10,131
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

9,832
zcash-stackzcashVerified publisher0.4.51 of 2See more

zcash-stack zcash 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
electriccoinco/lightwalletd:v0.5.42ae3a551e111
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,866
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

4,566
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

7,713
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

3,226
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

25,507
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,487
gotenbergadnoctemVerified publisher0.5.01 of 1See more

gotenberg adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.37.0f29984bd1e22
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,491
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,577
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

29,687
bootaerokube1.0.11 of 4See more

boot aerokube 1.0.1

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/aerokube/keygen:1.0.1578934444f04
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

7,915
aerospike-kubernetes-operatoraerospike4.5.01 of 1See more

aerospike-kubernetes-operator aerospike 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
aerospike/aerospike-kubernetes-operator:4.5.070a9eeb991b8
nghttp2@1.68.0-3.el10_2.1
0:1.68.0-3.el10_2.2

Open the chart page →

617
ahnlich-dbahnlich-dbVerified publisher0.1.11 of 1See more

ahnlich-db ahnlich-db 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/deven96/ahnlich-db:latest45d8b5aab491
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,566
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,685
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
airbyte/manifest-server:7.23.73b3a670af168
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

12,481
aktoakto0.2.02 of 7See more

akto akto 0.2.0

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

13,689
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2

Open the chart page →

9,400
akto-central-setupakto1.1.101 of 5See more

akto-central-setup akto 1.1.10

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

5,079
akto-hybrid-redactakto1.44.61 of 5See more

akto-hybrid-redact akto 1.44.6

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

4,089
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

2,797
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

3,181
akto-mini-testingakto1.45.72 of 5See more

akto-mini-testing akto 1.45.7

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
nghttp2@1.52.0-1+deb12u3
no fix listed
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

6,447
akto-mini-testing-kafkaakto1.42.12 of 5See more

akto-mini-testing-kafka akto 1.42.1

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,395
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,843
akto-protectionakto0.1.02 of 4See more

akto-protection akto 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

11,283
akto-regional-setupakto1.3.12 of 9See more

akto-regional-setup akto 1.3.1

2 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

7,786
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

1,469
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

4,856
akto-threat-backendakto0.1.51 of 2See more

akto-threat-backend akto 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

1,548
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

1,580
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

3,481
esphomealekcVerified publisher2.8.11 of 1See more

esphome alekc 2.8.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
esphome/esphome:2026.8.285abea33854b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,143
komodoalekcVerified publisher3.1.01 of 1See more

komodo alekc 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,930
alertigatealertigate0.5.11 of 1See more

alertigate alertigate 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/feresberbeche/alertigate:1.2.1628d49e0e01b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,505
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,898
flaresolverralexmorbo-flaresolverrVerified publisher0.2.01 of 1See more

flaresolverr alexmorbo-flaresolverr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

27,282
nginx-sni-proxyalexpressoVerified publisher1.0.21 of 1See more

nginx-sni-proxy alexpresso 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4

Open the chart page →

3,685
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hazelcast/management-center:5.3.2f9d34300d330
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

28,212
anchore-admission-controlleranchore-charts0.8.51 of 2See more

anchore-admission-controller anchore-charts 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

7,559
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

5,838
stalwartandibraeuVerified publisher1.0.21 of 1See more

stalwart andibraeu 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.16.1425001929f36a
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,566
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

7,265
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

3,872

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pozetroninc/keydb:v6.0.1653ae64f29da8
nghttp2@1.30.0-1ubuntu1
no fix listed
1
praravind1801/helmimages:3.0.0f29d637b9ce1
nghttp2@1.52.0-1+deb12u1
no fix listed
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
nghttp2@1.52.0-1+deb12u1
no fix listed
1
prefecthq/prefect:3.8.6-python3.11f518ebb9c353
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
nghttp2@1.64.0-1.1
no fix listed
1
project2team4/react:latest3ff031a08887
nghttp2@1.40.0-1build1
no fix listed
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
prowlercloud/prowler-api:5.31.14f252d579be2
nghttp2@1.52.0-1+deb12u3
no fix listed
1
pschichtel/mindustry-server:v145.1b543e9c2d371
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
nghttp2@1.43.0-6.el9_7.1
0:1.43.0-6.el9_8.2
1
psorab/elibrary:latest53b68896c4ce
nghttp2@1.40.0-1build1
no fix listed
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
nghttp2@1.40.0-1build1
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
quickwit/quickwit:v0.8.1d29332bdadcc
nghttp2@1.52.0-1+deb12u1
no fix listed
1
qumine/minecraft-server:v0.1.15c0b650d51132
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
rabeh/apibootspring:1.0941007b6946e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
rancher/harvester-csi-driver:v0.2.9f9099b5ef8cb
nghttp2@1.64.0-160000.3.1
1.64.0-160000.4.1
1
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
nghttp2@1.64.0-160000.3.1
1.64.0-160000.4.1
1
razorbladex401/dayz:latest6a4d79248e7d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
razzy10/product-service:latest702e411956db
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
readysettech/sqp:latest588f3507280e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
readysettech/sqp-duckdb:latest67a83203ce60
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
redash/redash:25.8.000d813437db5
nghttp2@1.52.0-1+deb12u2
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
nghttp2@1.52.0-1+deb12u2
no fix listed
1
redimp/otterwiki:2778bf30da3da
nghttp2@1.52.0-1+deb12u3
no fix listed
1
redislabs/operator:8.0.18-119078e713bb6a
nghttp2@1.43.0-6.el9_7.1
0:1.43.0-6.el9_8.2
1
redpandadata/redpanda:latest468bd13a9f2b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
replicated/replicated-sdk:1.0.0-beta.318751b4963250
nghttp2@1.63.0-r0
1.70.0-r0
1
resurfaceio/resurface:3.7.84d5cda2f64109
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
rezachalak/bzen-mongo:1.0.034f694325191
nghttp2@1.40.0-1ubuntu0.1
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
nghttp2@1.52.0-1+deb12u2
no fix listed
1
rm3l/dev-feed-api:latest9a7f732245a3
nghttp2@1.43.0-5.el9_2.1
0:1.43.0-6.el9_8.2
1
rm3l/mac-oui:1.8.03a5e1f95c132
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
nghttp2@1.40.0-1build1
no fix listed
1
robotshop/rs-mongodb:latest119b545823cd
nghttp2@1.40.0-1build1
no fix listed
1
robustadev/kubewatch:v2.9.00457a51e36e8
nghttp2@1.63.0-r0
1.70.0-r0
1
rocketchat/freeswitch:stablecfba5c20a5cc
nghttp2@1.52.0-1+deb12u2
no fix listed
1
rosette/root-rli:7.23.21.c82.0a4467d3bb211
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
rtuszik/photon-docker:2.4.021549c60f9e6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
santisbon/speedtest:latest8ee3a1697227
nghttp2@1.52.0-1
no fix listed
1
sarwansharma/minio:v359d1da9385d1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
nghttp2@1.52.0-1+deb12u1
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nghttp2@1.52.0-1
no fix listed
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.