StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,259
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

8,154
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

14,910
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

30,150
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

29,151
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,152
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

12,999
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

66,542
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,957
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,152
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

12,999
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

66,542
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

4,969
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,957
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
no fix listed
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

27,608
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

19,063
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233
adventurelogdjjudas21Verified publisher0.1.12 of 3See more

adventurelog djjudas21 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
nghttp2@1.64.0-1.1+deb13u1
no fix listed
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
nghttp2@1.69.0-r0
1.70.0-r0

Open the chart page →

7,480
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
nghttp2@1.52.0-1
no fix listed

Open the chart page →

7,167
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

17,053
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,144
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,885
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nghttp2@1.52.0-1
no fix listed

Open the chart page →

13,031
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,626
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,626
dnation-kubernetes-monitoring-stackdnationcloud4.0.23 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

3 of the 17 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

21,455
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

8,991
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,307
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

3,166
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

24,975
healthchecksdoubanVerified publisher1.0.101 of 2See more

healthchecks douban 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
healthchecks/healthchecks:latestaa08a61b0dcf
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,721
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,831
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
no fix listed
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

24,714
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
quay.io/keycloak/keycloak:20.0054ef67eb7da
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

55,988
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
ghcr.io/ctron/kubectl:1.25e37d61b5277c
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

30,759
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,914
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,283
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,426
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

19,820
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,251
base-consensusdysnixVerified publisher0.2.01 of 1See more

base-consensus dysnix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4

Open the chart page →

1,743
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

13,422
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

11,482
orion-ldeclipse-aeriosVerified publisher1.0.02 of 2See more

orion-ld eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fiware/orion-ld:1.10.03c490a746f65
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
library/mongo:7.0.12ae1cf99fa7bf
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

9,805
redpandaeclipse-aeriosVerified publisher5.7.81 of 4See more

redpanda eclipse-aerios 5.7.8

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
redpandadata/redpanda:latest468bd13a9f2b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,551
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,995
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
nghttp2@1.52.0-1+deb12u1
no fix listed
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
nghttp2@1.52.0-1+deb12u1
no fix listed
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
nghttp2@1.52.0-1+deb12u1
no fix listed
1
splunk/splunk-operator:2.0.0c4e0d3146226
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
sslhep/servicex_app:v1.8.51d12f943cec5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2api:3.86f56d239d280
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2auth:3.833ecfda16608
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2web:3.809989a26c8b7
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
stakater/workshop-operator:v0.0.3897bf456cc97c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
stalwartlabs/stalwart:v0.16.1425001929f36a
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
stalwartlabs/stalwart:v0.16.22388dcb75a707
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
stashapp/stash-box:latesta534c8afdf39
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
statcan/ckan:2.93921305425b8
nghttp2@1.40.0-1build1
no fix listed
1
strangebee/thehive:5.7.6-1e77b713124dd
nghttp2@1.52.0-1+deb12u3
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
nghttp2@1.40.0-1build1
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
substratusai/verba:v0.4.0-baseURL261695be635eb
nghttp2@1.52.0-1+deb12u1
no fix listed
1
supabase/logflare:latest49bfe526f1b4
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
supabase/realtime:v2.102.3aa1c92c0cf32
nghttp2@1.52.0-1+deb12u3
no fix listed
1
supabase/realtime:v2.33.8d207e6e23ad3
nghttp2@1.52.0-1+deb12u1
no fix listed
1
supabase/realtime:latestd3aa0c86c7b3
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
nghttp2@1.52.0-1+deb12u1
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
nghttp2@1.52.0-1+deb12u3
no fix listed
1
supabase/studio:latest94a2a9d2906e
nghttp2@1.52.0-1+deb12u3
no fix listed
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nghttp2@1.40.0-1ubuntu0.1
no fix listed
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
nghttp2@1.52.0-1+deb12u1
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
nghttp2@1.40.0-1ubuntu0.1
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
nghttp2@1.52.0-1+deb12u2
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
nghttp2@1.52.0-1+deb12u2
no fix listed
1
tautulli/tautulli:latest670e68dd9efc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.