StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,790 indexed, latest versions
Container images
1,612
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,790 indexed charts deploy, on 1,612 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,208
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
web-chartjaeeyun-ktcloudlab0.1.01 of 1See more

web-chart jaeeyun-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
nginx-chartjaeki-nginx0.1.01 of 1See more

nginx-chart jaeki-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,864
jasperjasperVerified publisher1.0.2031 of 2See more

jasper jasper 1.0.203

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

9,210
jasper-uijasperVerified publisher1.0.341 of 1See more

jasper-ui jasper 1.0.34

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,581
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,103
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

4,511
jellyfinjellyfin--jellyfin-helm3.0.01 of 1See more

jellyfin jellyfin--jellyfin-helm 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.717285f9cce63
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,022
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.3

Open the chart page →

9,854
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,498
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

12,858
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

5,259
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

7,838
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

6,655
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

6,637
nginx-chartjinbok-nginx0.1.01 of 1See more

nginx-chart jinbok-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
nginx-chartjiungVerified publisher0.1.01 of 1See more

nginx-chart jiung 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
nginx-chartjongh09160.1.01 of 1See more

nginx-chart jongh0916 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
image-storage-servicejtektVerified publisher0.4.33 of 4See more

image-storage-service jtekt 0.4.3

3 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
nghttp2@1.52.0-1+deb12u1
no fix listed
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

22,728
shinsei-managerjtektVerified publisher0.2.07 of 8See more

shinsei-manager jtekt 0.2.0

7 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
nghttp2@1.52.0-1+deb12u2
no fix listed
moreillon/group-manager:latest3caa8f710ee0
nghttp2@1.52.0-1+deb12u2
no fix listed
moreillon/group-manager-front:latest5f0a38498271
nghttp2@1.64.0-1.1
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
no fix listed
moreillon/user-manager-front:v5.0.3b067dbbbb6af
nghttp2@1.52.0-1
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
nghttp2@1.52.0-1+deb12u1
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

63,822
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
no fix listed

Open the chart page →

16,680
jupyter-hub-customizationsjupyter-jscVerified publisher0.27.171 of 4See more

jupyter-hub-customizations jupyter-jsc 0.27.17

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:1.291881968aff6f
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,412
jupyter-nginxjupyter-jscVerified publisher0.1.31 of 1See more

jupyter-nginx jupyter-jsc 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,531
jwks-mergejwks-merge0.1.01 of 2See more

jwks-merge jwks-merge 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,055
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

10,570
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,691
jellyfink8s-chartsVerified publisher0.2.41 of 1See more

jellyfin k8s-charts 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.696b09723b22f
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,127
palworld-serverk8s-chartsVerified publisher1.2.11 of 1See more

palworld-server k8s-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,493
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

6,161
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

8,899
flaresolverrk8s-home-lab-repo6.2.01 of 1See more

flaresolverr k8s-home-lab-repo 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

27,554
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

9,135
vaultwardenk8s-home-lab-repo6.2.31 of 1See more

vaultwarden k8s-home-lab-repo 6.2.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.35.79a8eec71f4a5
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

2,877
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

9,835
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

14,872
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

7,360
kadeck-teamskadeck1.1.211 of 1See more

kadeck-teams kadeck 1.1.21

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
xeotek/kadeck:6.3.439a3b37a17c5
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,617
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,319
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

4,591
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,498
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,137
k10restorekastenVerified publisher8.0.141 of 1See more

k10restore kasten 8.0.14

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,485
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

16,484
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

32,812
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

8,877
web-chartkcilab0.1.01 of 1See more

web-chart kcilab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,849
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,245
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

5,066
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

12,538
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

10,297

Container images carrying it

1,612 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.3
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/minio/directpv:v4.0.84560083eb77d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/nmstate/kubernetes-nmstate-operator:v0.87.04dce694f01ea
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/open-cluster-management/managed-serviceaccount:v0.10.0d6284bd7765a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3
1
quay.io/openshift/origin-cli:4.66722d5041b47
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
nghttp2@1.33.0-3.el8_2.2
0:1.33.0-6.el8_10.3
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-6.el8_10.3
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
nghttp2@1.64.0-1.1
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/projectquay/clair:4.9.023329c3368e4
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_8.2
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_8.2
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/strimzi/operator:0.45.158c727cd2e68
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
nghttp2@1.52.0-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
nghttp2@1.64.0-1.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
nghttp2@1.52.0-1+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.