StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
factorio-server-chartsfactorio-server-chartsVerified publisher2.5.21 of 1See more

factorio-server-charts factorio-server-charts 2.5.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
factoriotools/factorio:lateste9227748c507
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,449
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/golang:latest512690a56605
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

8,473
localstacklocalstack0.7.01 of 1See more

localstack localstack 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,192
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

9,697
oneuptimeoneuptimeOfficialVerified publisher13.0.42 of 7See more

oneuptime oneuptime 13.0.4

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
oneuptime/probe:release6b2d98713711
nghttp2@1.52.0-1+deb12u3
no fix listed
oneuptime/runner:release4accc516d800
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

10,896
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

5,679
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

3,422
stalwart-mailstalwart-mailVerified publisher2.0.101 of 1See more

stalwart-mail stalwart-mail 2.0.10

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,382
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

15,607
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,917
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,853
glasskube-operatorglasskubeOfficialVerified publisher0.12.22 of 3See more

glasskube-operator glasskube 0.12.2

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

11,971
milvusmilvus-helm5.0.281 of 4See more

milvus milvus-helm 5.0.28

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

10,764
coreneuvectorchartsVerified publisher2.11.13 of 5See more

core neuvectorcharts 2.11.1

3 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
neuvector/controller:5.6.1ae45c394f1ac
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1
neuvector/enforcer:5.6.1aa2137cc90ec
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1
neuvector/updater:0.0.14a28b887039b1
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1

Open the chart page →

884
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
prefecthq/prefect:3.8.6-python3.11f518ebb9c353
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,448
rocketmqrocketmq12.6.02 of 2See more

rocketmq rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

6,385
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

18,570
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

6,675
codefreshcodefresh-onpremOfficialVerified publisher2.12.132 of 42See more

codefresh codefresh-onprem 2.12.13

2 of the 42 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
nghttp2@1.52.0-1+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.39e635efba431
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

14,615
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
nghttp2@1.64.0-1.1+deb13u1
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,747
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,716
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2api:3.86f56d239d280
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2auth:3.833ecfda16608
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2notifier:3.8f190a6212195
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2web:3.809989a26c8b7
nghttp2@1.40.0-1ubuntu0.2
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
nghttp2@1.40.0-1ubuntu0.2
no fix listed

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.02 of 14See more

supabase tokens-studio 1.0.0

2 of the 14 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
supabase/realtime:v2.33.8d207e6e23ad3
nghttp2@1.52.0-1+deb12u1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

23,263
polarisapache-polarisOfficialVerified publisher1.3.0-incubating1 of 1See more

polaris apache-polaris 1.3.0-incubating

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/polaris:lateste66366e783f1
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

473
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

8,530
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4

Open the chart page →

1,749
budibasebudibase0.0.0-master2 of 7See more

budibase budibase 0.0.0-master

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
nghttp2@1.52.0-1+deb12u2
no fix listed
budibase/proxy:3.41.38d780b6ee602
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

10,810
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

7,896
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,412
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,453
devtron-operatordevtron0.23.31 of 11See more

devtron-operator devtron 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

5,396
nextcloudgroundhog2k0.22.51 of 3See more

nextcloud groundhog2k 0.22.5

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,538
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

23,289
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

3,434
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,031
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,665
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

4,344
syftopenmined0.9.52 of 6See more

syft openmined 0.9.5

2 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
nghttp2@1.64.0-r1
1.70.0-r0
openmined/syft-frontend:0.9.5d11524a3854a
nghttp2@1.64.0-r1
1.70.0-r0

Open the chart page →

17,306
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

8,510
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

14,276
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,831
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
nghttp2@1.64.0-1.1+deb13u1
no fix listed
thingsboard/tbmq-node:2.4.070661025dba5
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,555
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

7,333
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

6,386
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,321
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

5,669
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
nghttp2@1.40.0-1build1
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
nghttp2@1.40.0-1build1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

30,811

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
no fix listed
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
nghttp2@1.52.0-1
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nghttp2@1.52.0-1
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
nghttp2@1.30.0-1ubuntu1
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
nghttp2@1.52.0-1+deb12u2
no fix listed
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
nghttp2@1.52.0-1+deb12u3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
nghttp2@1.64.0-1.1+e1
1.64.0-1.1+e2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
nghttp2@1.52.0-1+deb12u2
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
no fix listed
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/aerokube/keygen:1.0.1578934444f04
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.