StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest20fde516ce31
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

4,893
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,698
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.4.4c0224a1adf7a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

15,606
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,135
openbaogitlabVerified publisher0.18.11 of 1See more

openbao gitlab 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,739
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

10,106
harp-proxyharp0.8.11 of 1See more

harp-proxy harp 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
makersquad/harp-proxy:0.8.1a40dd258c527
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

6,092
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

4,750
hello-helmhellok8s0.1.01 of 2See more

hello-helm hellok8s 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,012
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

8,773
matomohelmforgeVerified publisher2.3.01 of 3See more

matomo helmforge 2.3.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/matomo:5.13.0-apache8e6bdd396496
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,711
vaultwardenhelmforgeVerified publisher1.13.11 of 1See more

vaultwarden helmforge 1.13.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,756
mywebapphelm-nginxVerified publisher0.1.01 of 1See more

mywebapp helm-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,977
helmuphelmupVerified publisher0.1.02 of 3See more

helmup helmup 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
nghttp2@1.52.0-1+deb12u1
no fix listed
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

16,532
hivemq-swarmhivemqOfficialVerified publisher0.2.701 of 1See more

hivemq-swarm hivemq 0.2.70

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hivemq/hivemq-swarm:4.54.0f9746d5d70fa
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4

Open the chart page →

1,388
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.42 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
quay.io/hpestorage/filex-csi-init:2.6.42d867eefb233
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

6,131
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

4,339
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

12,461
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,509
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

15,749
elasticinseefrlab2.2.02 of 2See more

elastic inseefrlab 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
no fix listed
library/kibana:7.17.3e2e2031c15be
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

17,365
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

11,794
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,415
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,489
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,716
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,571
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

9,318
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

7,393
ombik8s-home-lab-repo12.2.11 of 1See more

ombi k8s-home-lab-repo 12.2.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/ombi:4.53.50caadf03b804
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4

Open the chart page →

1,460
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
kafkakraft/kafka-controller:3.7.0f261ad288fce
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
kafkakraft/kafkakraft:3.7.02e4b593b878b
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

14,250
web-chartkbt-ktcloudlab0.1.01 of 1See more

web-chart kbt-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,515
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,795
app-componentkeltio-helm-chartsVerified publisher3.14.01 of 1See more

app-component keltio-helm-charts 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,234
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

5,302
glpikitsune-itopsVerified publisher1.0.71 of 3See more

glpi kitsune-itops 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
glpi/glpi:latest4b681082a79e
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,878
powerdns-recursorklicktippVerified publisher0.4.101 of 1See more

powerdns-recursor klicktipp 0.4.10

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
powerdns/pdns-recursor-54:5.4.533aadc74a8d6
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,886
knot-resolverknot-resolverVerified publisher1.0.51 of 1See more

knot-resolver knot-resolver 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cznic/knot-resolver:v6.4.2fe71c5214fdc
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,061
kokukokuVerified publisher1.0.02 of 7See more

koku koku 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

12,063
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

20,424
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
nghttp2@1.43.0-1ubuntu0.3
1.43.0-1ubuntu0.4

Open the chart page →

9,975
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,749
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

114,025
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,551
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,011

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
no fix listed
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
nghttp2@1.52.0-1
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nghttp2@1.52.0-1
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
nghttp2@1.30.0-1ubuntu1
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
nghttp2@1.52.0-1+deb12u2
no fix listed
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
nghttp2@1.52.0-1+deb12u3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
nghttp2@1.64.0-1.1+e1
1.64.0-1.1+e2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
nghttp2@1.52.0-1+deb12u2
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
nghttp2@1.52.0-1+deb12u2
no fix listed
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
nghttp2@1.52.0-1+deb12u1
no fix listed
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/aerokube/keygen:1.0.1578934444f04
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.