StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,790 indexed, latest versions
Container images
1,612
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,790 indexed charts deploy, on 1,612 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,208
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

42,325
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,591
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,461
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,261
apishiftapishiftVerified publisher0.3.02 of 4See more

apishift apishift 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

2,961
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

6,256
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

19,788
app-mobilityappmo0.1.02 of 5See more

app-mobility appmo 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,541
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,655
aceappscodeVerified publisher2026.9.111 of 2See more

ace appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,957
ace-installerappscodeVerified publisher2026.9.111 of 2See more

ace-installer appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,296
ace-installer-certifiedappscodeVerified publisher2026.9.111 of 2See more

ace-installer-certified appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,296
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,655
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

647
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

647
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,063
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

4,005
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

15,718
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

17,122
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,404
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

912
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,655
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,050
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,575
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

37,629
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,313
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
no fix listed

Open the chart page →

5,680
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,902
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,558
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

7,359
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,956
arlas-aiasarlas-stackVerified publisher28.8.07 of 22See more

arlas-aias arlas-stack 28.8.0

7 of the 22 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

40,580
titilerarlas-stackVerified publisher28.8.01 of 1See more

titiler arlas-stack 28.8.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,466
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

23,425
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

3,571
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
no fix listed
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

22,663
assemblylineassemblylineVerified publisher7.4.193 of 12See more

assemblyline assemblyline 7.4.19

3 of the 12 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable19c914f21a41d7
nghttp2@1.52.0-1+deb12u3
no fix listed
cccs/assemblyline-socketio:4.7.4.stable19caf40394bd17
nghttp2@1.52.0-1+deb12u3
no fix listed
cccs/assemblyline-ui:4.7.4.stable190426ed7884a2
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

12,666
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

14,823
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

9,411
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

13,369
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

10,127
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

18,357
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

8,052
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

7,985
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

5,371
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
no fix listed
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

45,656
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
no fix listed
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

14,013
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

32,638
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,429
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

6,958

Container images carrying it

1,612 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
nghttp2@1.43.0-5.el9_4.3
0:1.43.0-6.el9_8.2
1
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/filex-csi-init:2.6.42d867eefb233
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
nghttp2@1.52.0-1+deb12u3
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
nghttp2@1.52.0-1+deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
nghttp2@1.52.0-1+deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
nghttp2@1.52.0-1+deb12u3
no fix listed
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/kuadrant/authorino-operator:v0.26.003b2acc469f4
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/kubev2v/forklift-operator:release-2.1268657c36c086
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/custom-rhcl-console:v0.1.270bb0cabd653
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.