StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,790 indexed, latest versions
Container images
1,612
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,790 indexed charts deploy, on 1,612 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,208
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
mac-ouirm3lVerified publisher1.25.01 of 1See more

mac-oui rm3l 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rm3l/mac-oui:1.8.03a5e1f95c132
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

1,975
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

10,165
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kimai/kimai2:2.67.03084f1e5ecdc
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,707
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

6,089
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,814
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

6,921
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,570
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

13,018
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,332
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

13,558
kyoorubxkubeVerified publisher0.1.103 of 9See more

kyoo rubxkube 0.1.10

3 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

30,428
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

38,166
immichsecustorVerified publisher2.0.51 of 1See more

immich secustor 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,081
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
ghcr.io/getsentry/snuba:26.7.210f8d164109b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

16,599
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
nghttp2@1.52.0-1+deb12u2
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

11,578
sigscale-csesigscale-cseOfficialVerified publisher1.4.221 of 1See more

sigscale-cse sigscale-cse 1.4.22

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sigscale/cse:latest67d0c886516b
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,297
sigscale-ocssigscale-ocsOfficialVerified publisher1.1.171 of 1See more

sigscale-ocs sigscale-ocs 1.1.17

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sigscale/ocs:latest3c1bdc9732e2
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,297
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,277
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,937
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
altinity/metrics-exporter:0.20.01a46d104406d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,420
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

46,047
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,204
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.41 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,604
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

5,699
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,450
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

11,459
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

25,005
stornxstornxVerified publisher1.1.12 of 9See more

stornx stornx 1.1.1

2 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
nghttp2@1.52.0-1+deb12u2
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

11,735
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,881
strimzi-drain-cleanerstrimzi1.6.11 of 1See more

strimzi-drain-cleaner strimzi 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

520
strimzi-drain-cleanerstrimzi-drain-cleaner1.6.11 of 1See more

strimzi-drain-cleaner strimzi-drain-cleaner 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

520
supabasesupabse0.8.02 of 11See more

supabase supabse 0.8.0

2 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
supabase/realtime:v2.102.3aa1c92c0cf32
nghttp2@1.52.0-1+deb12u3
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

18,327
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,263
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
nghttp2@1.64.0-1.1+deb13u1+dhi2
no fix listed

Open the chart page →

2,563
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
no fix listed

Open the chart page →

9,119
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
no fix listed

Open the chart page →

9,119
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

4,075
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
nghttp2@1.64.0-1.1+deb13u1
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,474
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,806
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,806
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

12,672
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,318
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

4,063
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,259
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
nghttp2@1.40.0-1ubuntu0.1
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

26,848
waldurwaldur-chartsVerified publisher8.1.21 of 3See more

waldur waldur-charts 8.1.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
opennode/waldur-mastermind:8.1.24c82b15d9042
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,901
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

15,986
cockroachdbwenerme22.0.31 of 3See more

cockroachdb wenerme 22.0.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3

Open the chart page →

763

Container images carrying it

1,612 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
no fix listed
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/feresberbeche/alertigate:1.2.1628d49e0e01b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/firecrawl/firecrawl:2.11.340529f38bab2c3
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.