StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,613
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

6,484
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

9,868
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
nghttp2@1.40.0-1ubuntu0.2
no fix listed

Open the chart page →

12,163
codercoderOfficialVerified publisher1.44.62 of 2See more

coder coder 1.44.6

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
coderenvs/timescale:1.44.676fd37fe6830
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

6,847
cortexcortex3.3.81 of 4See more

cortex cortex 3.3.8

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:1.3105b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,921
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

4,951
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

5,602
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,179
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

2,913
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

8,685
nessienessie0.108.41 of 1See more

nessie nessie 0.108.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

222
passboltpassbolt2.1.11 of 6See more

passbolt passbolt 2.1.1

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

13,455
redis-enterprise-operatorredis-enterprise-operator-officialOfficialVerified publisher8.0.18-111 of 1See more

redis-enterprise-operator redis-enterprise-operator-official 8.0.18-11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
redislabs/operator:8.0.18-119078e713bb6a
nghttp2@1.43.0-6.el9_7.1
0:1.43.0-6.el9_8.2

Open the chart page →

914
thehivestrangebee-helmOfficialVerified publisher1.0.63 of 7See more

thehive strangebee-helm 1.0.6

3 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
no fix listed
strangebee/thehive:5.7.6-1e77b713124dd
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

16,161
truenas-csptruenas-cspVerified publisher1.2.45 of 11See more

truenas-csp truenas-csp 1.2.4

5 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

5,851
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

14,266
minecraft-overvieweralphani-helm-chartsVerified publisher0.1.01 of 3See more

minecraft-overviewer alphani-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,392
baserowbaserow-chartVerified publisher1.0.562 of 6See more

baserow baserow-chart 1.0.56

2 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
nghttp2@1.64.0-1.1+deb13u1
no fix listed
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

17,346
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
nghttp2@1.40.0-1build1
no fix listed
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

53,012
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dolibarr/dolibarr:22.0.47ad88fc9b13c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

9,154
seafiledatamateVerified publisher0.6.02 of 6See more

seafile datamate 0.6.0

2 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
nghttp2@1.52.0-1+deb12u1
no fix listed
datamate/seafile-professional:11.0.202dd66b722464
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

27,358
jellyfindjjudas21Verified publisher4.0.81 of 1See more

jellyfin djjudas21 4.0.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,615
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,578
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
nghttp2@1.43.0-1ubuntu0.3
1.43.0-1ubuntu0.4

Open the chart page →

14,043
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,800
glpiglpi-conteiner0.1.02 of 3See more

glpi glpi-conteiner 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
nghttp2@1.64.0-1.1+deb13u1
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

12,270
alloy-operatorgrafana0.7.11 of 1See more

alloy-operator grafana 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

420
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dolibarr/dolibarr:24.0.069ec52e3b7ef
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,136
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

9,535
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,654
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

3,396
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
apache/hertzbeat-collector:1.8.0a2bab1be574c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

14,109
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,460
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

1,724
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

6,354
keycloak-operatorkeycloak-operatorVerified publisher0.0.41 of 1See more

keycloak-operator keycloak-operator 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,662
percona-xtradb-clusterkfirfer1.5.101 of 3See more

percona-xtradb-cluster kfirfer 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,956
kubeflowkubeflow1.6.23 of 45See more

kubeflow kubeflow 1.6.2

3 of the 45 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
nghttp2@1.30.0-1ubuntu1
no fix listed
istio/proxyv2:1.14.1df69c1a7af7c
nghttp2@1.40.0-1build1
no fix listed
library/python:3.7eedf63967cdb
nghttp2@1.52.0-1
no fix listed

Open the chart page →

97,040
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

10,569
testkubekubeshop2.13.21 of 5See more

testkube kubeshop 2.13.2

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kubeshop/testkube-minio:2025.10d8e1af6aca99
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

5,012
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

5,833
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,968
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gradiant/open5gs-dbctl:0.10.3332031245fce
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

9,300
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

8,767
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
nghttp2@1.40.0-1ubuntu0.2
no fix listed

Open the chart page →

10,536
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
nghttp2@1.52.0-1+deb12u3
no fix listed
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

5,493
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

19,363
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,996
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
nghttp2@1.52.0-1
no fix listed

Open the chart page →

9,753

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
ghcr.io/caninehq/canine:latesta058034ca006
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/chmouel/gosmee:v0.32.060b8db1f68cc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
nghttp2@1.64.0-160000.3.1
1.64.0-160000.4.1
1
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/containers/kubernetes-mcp-server:v0.0.666d650f4bd6ac
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/dakera-ai/dakera:0.11.101af610992a416
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/dask/dask:2024.1.0080150de7d86
nghttp2@1.40.0-1ubuntu0.2
no fix listed
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/deven96/ahnlich-db:latest45d8b5aab491
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.