StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
matrixzekker6Verified publisher3.30.01 of 4See more

matrix zekker6 3.30.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.160.078de1d10bef0
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,568
eshoponabpabp-charts1.0.01 of 15See more

eshoponabp abp-charts 1.0.0

1 of the 15 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2699d652ed674
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

19,805
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

8,251
vaultwardenandrenarchyVerified publisher6.27.01 of 1See more

vaultwarden andrenarchy 6.27.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,756
limesurveyarea-42Verified publisher0.3.941 of 2See more

limesurvey area-42 0.3.94

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
adamzammit/limesurvey:7.1.0f48962e1528c
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,678
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
nghttp2@1.33.0-3.el8_2.2
0:1.33.0-6.el8_10.3

Open the chart page →

9,052
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

8,007
collabora-codechrisingenhaag2.6.01 of 1See more

collabora-code chrisingenhaag 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
collabora/code:23.05.10.1.105299b452f7f
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

4,184
coder-observabilitycoder-observabilityVerified publisher0.7.32 of 21See more

coder-observability coder-observability 0.7.3

2 of the 21 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

24,698
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2

Open the chart page →

7,476
convertigoconvertigoOfficialVerified publisher8.4.32 of 5See more

convertigo convertigo 8.4.3

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
nghttp2@1.52.0-1+deb12u2
no fix listed
library/couchdb:3.4.22817ad50b5c5
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

17,475
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

3,081
cosmocosmo-platformOfficialVerified publisher0.20.02 of 10See more

cosmo cosmo-platform 0.20.0

2 of the 10 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

27,984
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

9,348
defectdojodefectdojo1.9.521 of 4See more

defectdojo defectdojo 1.9.52

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
defectdojo/defectdojo-django:3.3.100c597abdbb535
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,340
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

4,194
edgelessdbedgelesssysVerified publisher0.3.21 of 1See more

edgelessdb edgelesssys 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

4,868
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.3

Open the chart page →

14,545
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.3

Open the chart page →

13,874
zabbix-agentfermosit0.0.51 of 1See more

zabbix-agent fermosit 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

2,408
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

5,302
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,729
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

22,812
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

14,001
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

9,666
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

10,202
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

10,676
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

11,873
apimgraviteeioVerified publisher4.12.192 of 4See more

apim graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
nghttp2@1.64.0-1.1+deb13u1
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,747
hpe-cosi-driverhpe-storageVerified publisher2.0.01 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,666
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,563
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
nghttp2@1.64.0-1.1
no fix listed
instill/mgmt-backend:d0933d4ebe12f77a3f9
nghttp2@1.64.0-1.1
no fix listed
instill/model-backend:611f0f2e980125e5ba5
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

30,920
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

4,357
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

7,375
webdavk8s-webdavVerified publisher0.0.71 of 1See more

webdav k8s-webdav 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/httpd:2.4979c38c2228d
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,693
kanister-operatorkanister0.118.01 of 1See more

kanister-operator kanister 0.118.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,163
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

7,285
radondb-mysqlkubesphere-testVerified publisher1.0.11 of 3See more

radondb-mysql kubesphere-test 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,381
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

11,630
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,940
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

17,755
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

3,794
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

5,066
observalobservalVerified publisher1.13.11 of 8See more

observal observal 1.13.1

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/observal/observal-api:1.13.1153b8b893232
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,839
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

5,224
oesopsmxVerified publisher4.0.327 of 25See more

oes opsmx 4.0.32

7 of the 25 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
nghttp2@1.64.0-1.1
no fix listed
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

107,899
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,334
psmdb-operatorpercona1.23.11 of 1See more

psmdb-operator percona 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
percona/percona-server-mongodb-operator:1.23.0feaff989e253
nghttp2@1.68.0-3.el10_2.1
0:1.68.0-3.el10_2.2

Open the chart page →

265
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,613

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
no fix listed
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/feresberbeche/alertigate:1.2.1628d49e0e01b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/firecrawl/firecrawl:2.11.33470453d7102cc
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.