CVE-2026-58055
MediumAdvisory
Published 28 Jun 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.003
- 17th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,677
- of 17,792 indexed, latest versions
- Container images
- 1,605
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: nghttp2 security update
Carried by container images the latest versions of 1,677 of 17,792 indexed charts deploy, on 1,605 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nghttp2deb | 1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more | 1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more | 1,206 |
| nghttp2apk | 1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more | 1.70.0-r0 | 11 |
| nghttp2rpm | 1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more | 0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more | 388 |
- OSV records
- CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
- Also known as
- CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1
Charts affected
1,677 by stars
Container images carrying it
1,605 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.gitlab.com/ | 301847adfe16 | nghttp2 | 0:1.43.0-6.el9_8.2 | 1 |
| registry.gitlab.com/ | fcf07d5ff7e2 | nghttp2 | 0:1.43.0-6.el9_8.2 | 1 |
| registry.gitlab.com/ | 03015f863a3e | nghttp2 | 0:1.68.0-3.el10_2.2 | 1 |
| registry.k8s.io/ | 0e64aedb0d0a | nghttp2 | no fix listed | 1 |
| registry.k8s.io/ | fd9722fd02e3 | nghttp2 | no fix listed | 1 |