StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,790 indexed, latest versions
Container images
1,612
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,790 indexed charts deploy, on 1,612 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,208
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

13,011
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

68,695
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

4,972
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed

Open the chart page →

33,180
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,959
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,242
rosette-serverrosette-serverOfficialVerified publisher3.6.01 of 3See more

rosette-server rosette-server 3.6.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rosette/root-rli:7.23.21.c82.0a4467d3bb211
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3

Open the chart page →

189
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

6,954
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
nghttp2@1.43.0-1ubuntu0.3
1.43.0-1ubuntu0.4

Open the chart page →

7,527
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

10,638
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

27,554
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,626
linkdingrubxkubeVerified publisher1.2.31 of 1See more

linkding rubxkube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.46.20c0a9a04c7eb
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,073
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,528
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

6,303
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

30,517
vaultwardenrubxkubeVerified publisher1.2.41 of 1See more

vaultwarden rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,766
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,102
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,746
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

8,733
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

9,631
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

7,403
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
nghttp2@1.52.0-1
no fix listed

Open the chart page →

19,707
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
nghttp2@1.52.0-1
no fix listed

Open the chart page →

16,739
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

16,193
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

8,100
pagessamanvithkaranth1.0.02 of 3See more

pages samanvithkaranth 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,242
speedtestsantisbon0.1.02 of 3See more

speedtest santisbon 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
nghttp2@1.52.0-1+deb12u2
no fix listed
santisbon/speedtest:latest8ee3a1697227
nghttp2@1.52.0-1
no fix listed

Open the chart page →

12,791
pagessarubits-pages1.0.02 of 3See more

pages sarubits-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,242
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

10,237
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,127
mongodbsb-helm-charts0.4.01 of 1See more

mongodb sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:7.0.140032d2ca20db
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

4,097
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

9,853
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,377
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,707
vaultwardensb-helm-charts0.4.01 of 1See more

vaultwarden sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.34.384fd8a47f58d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

3,340
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

13,618
factorioschichtelVerified publisher0.1.11 of 1See more

factorio schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

2,994
mindustryschichtelVerified publisher0.1.11 of 1See more

mindustry schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
pschichtel/mindustry-server:v145.1b543e9c2d371
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,268
photonschichtelVerified publisher0.2.01 of 1See more

photon schichtel 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rtuszik/photon-docker:2.4.021549c60f9e6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,870
s3-backupschichtelVerified publisher0.10.01 of 1See more

s3-backup schichtel 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,372
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,567
vaultwardenschichtelVerified publisher0.9.21 of 1See more

vaultwarden schichtel 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,766
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
nghttp2@1.64.0-1.1+deb13u1
no fix listed
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

8,275
otterwikischmitzis0.1.01 of 1See more

otterwiki schmitzis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
redimp/otterwiki:2778bf30da3da
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,246
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

6,167
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,022
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2

Open the chart page →

10,445
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,469

Container images carrying it

1,612 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
no fix listed
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/feresberbeche/alertigate:1.2.1628d49e0e01b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/firecrawl/firecrawl:2.11.340529f38bab2c3
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.