StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,661
of 17,790 indexed, latest versions
Container images
1,595
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,661 of 17,790 indexed charts deploy, on 1,595 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,193
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more391
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,661 by stars
ChartLatestAffected imagesRadar Score
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,644
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

12,531
mysqld-exporterchoerodon0.1.01 of 1See more

mysqld-exporter choerodon 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,440
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,006
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

4,858
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

6,487
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
matterlabs/external-node:v24.0.06cbfea4c694a
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

5,550
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

1,618
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

12,021
helmchartclouddrove1.4.01 of 1See more

helmchart clouddrove 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
kube-acp-stackcloudentity2.28.02 of 7See more

kube-acp-stack cloudentity 2.28.0

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

20,936
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

29,922
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

23,683
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,831
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

25,152
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

25,454
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

29,594
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

18,256
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

12,505
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

12,176
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,640
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,552
galaxy-depscloudve1.1.11 of 7See more

galaxy-deps cloudve 1.1.1

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,543
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

16,117
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,994
terminalmancloudve0.3.41 of 1See more

terminalman cloudve 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cloudve/ttyd:latestd79c1c5881c0
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

13,170
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,457
chowdacluster-deploy0.2.01 of 1See more

chowda cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,801
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,521
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

8,806
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,136
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

6,926
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

3,918
web-chartcms-ktcloudlab0.1.01 of 1See more

web-chart cms-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
appcnapVerified publisher1.2.01 of 1See more

app cnap 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

4,616
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

19,380
cobbler-tftpcobbler0.1.11 of 1See more

cobbler-tftp cobbler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
nghttp2@1.64.0-160000.3.1
1.64.0-160000.4.1

Open the chart page →

304
codehubcodehubVerified publisher6.2.182 of 5See more

codehub codehub 6.2.18

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
no fix listed
jupyterhub/jupyterhub:5.4.63974ba945e65
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4

Open the chart page →

13,286
cohdicohdi0.2.21 of 3See more

cohdi cohdi 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,680
genericcolearendt0.2.71 of 1See more

generic colearendt 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

5,958
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

8,251
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

4,682
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,994
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

14,587
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,814
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,183
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:6.1.078c190f4472c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

58,856

Container images carrying it

1,595 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/lloesche/valheim-server:latest20fde516ce31
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/microboxlabs/miot-calendar:latest-jvm7157cdc0bf5b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
ghcr.io/open-webui/open-terminal:0.13.0-slimdec44673c865
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
nghttp2@1.40.0-1build1
no fix listed
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
nghttp2@1.52.0-1+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
nghttp2@1.52.0-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
nghttp2@1.64.0-1.1
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
nghttp2@1.52.0-1+deb12u3
no fix listed
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2
1
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.