StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,677
of 17,781 indexed, latest versions
Container images
1,606
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,677 of 17,781 indexed charts deploy, on 1,606 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,203
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more392
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,677 by stars
ChartLatestAffected imagesRadar Score
jenkinsjenkinsciOfficialVerified publisher5.9.581 of 2See more

jenkins jenkinsci 5.9.58

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-jdk21c1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,665
longhornlonghorn1.12.13 of 3See more

longhorn longhorn 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.183b79f57043f
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1
longhornio/longhorn-share-manager:v1.12.1efaf47aeb4e8
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1
longhornio/longhorn-ui:v1.12.103a3ce6673df
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1

Open the chart page →

554
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,507
rancherrancher-stable2.15.11 of 2See more

rancher rancher-stable 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1

Open the chart page →

1,456
giteagiteaOfficialVerified publisher12.7.01 of 4See more

gitea gitea 12.7.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

8,811
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

6,556
authentikgoauthentikOfficialVerified publisher2026.8.21 of 1See more

authentik goauthentik 2026.8.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,257
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
nghttp2@1.52.0-1+deb12u3
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

7,894
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

30,159
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

11,367
falcofalcosecurity9.1.02 of 3See more

falco falcosecurity 9.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
falcosecurity/falco:0.44.1d0cfe422d6ac
nghttp2@1.69.0-r0
1.70.0-r0
falcosecurity/falco-driver-loader:0.44.17df783d5269a
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

5,227
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

7,713
zabbixzabbix-communityVerified publisher7.1.04 of 5See more

zabbix zabbix-community 7.1.0

4 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

13,664
graylogkong-zVerified publisher3.0.321 of 5See more

graylog kong-z 3.0.32

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,699
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,092
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,366
vaultwardengissilabs1.4.21 of 1See more

vaultwarden gissilabs 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,744
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

5,552
zammadzammadOfficialVerified publisher18.0.51 of 5See more

zammad zammad 18.0.5

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

6,887
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

9,145
milvusmilvus4.0.313 of 5See more

milvus milvus 4.0.31

3 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
nghttp2@1.40.0-1build1
no fix listed
milvusdb/milvus:v2.2.13a3a55e1c1497
nghttp2@1.40.0-1build1
no fix listed
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

32,259
cockroachdbcockroachdbVerified publisher22.0.31 of 3See more

cockroachdb cockroachdb 22.0.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3

Open the chart page →

744
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,622
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

1,127
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

2,705
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

4,802
rancherrancher-latest2.15.11 of 2See more

rancher rancher-latest 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1

Open the chart page →

1,456
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

19,391
dragonflydragonflyVerified publisher1.8.41 of 3See more

dragonfly dragonfly 1.8.4

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.4a1b52779c4dd
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,787
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3

Open the chart page →

2,119
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

392
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

3,606
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,927
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
nghttp2@1.52.0-1+deb12u3
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
nghttp2@1.52.0-1+deb12u3
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
langgenius/dify-sandbox:0.2.15750e1111426e
nghttp2@1.68.1-1
no fix listed
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

22,002
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3

Open the chart page →

925
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

1,869
oktetooktetoOfficialVerified publisher0.0.0-2026-08-031 of 10See more

okteto okteto 0.0.0-2026-08-03

1 of the 10 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-033e56bdd1b90d
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,750
yourlsyourlsOfficialVerified publisher8.9.111 of 2See more

yourls yourls 8.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.69b220ea83329
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,203
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

1,346
gocdgocdOfficialVerified publisher2.18.12 of 2See more

gocd gocd 2.18.1

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gocd/gocd-agent-wolfi:v26.1.0753b9f696f45
nghttp2@1.69.0-r0
1.70.0-r0
gocd/gocd-server:v26.1.0720d1012b93f
nghttp2@1.69.0-r0
1.70.0-r0

Open the chart page →

1,362
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.02 of 5See more

openproject openproject-helm-charts 13.11.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
nghttp2@1.52.0-1+deb12u2
no fix listed
openproject/openproject:17.8.0-slim48952034215d
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

19,926
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

11,384
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
nghttp2@1.52.0-1+deb12u3
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

7,210
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

33,725
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,543
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

8,364
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

5,240
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,987
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
nghttp2@1.40.0-1ubuntu0.2
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

12,746
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,993

Container images carrying it

1,606 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
akeyless/base:latest759e4289fae8
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
akeyless/base-rhel:0.0.14ba8900a0061
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
aktosecurity/data-ingestion-service213aded7adc5
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2
1
alazidis/stornx:1.1.1602d4f7f090c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
nghttp2@1.52.0-1+deb12u2
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
nghttp2@1.30.0-1ubuntu1
no fix listed
1
alquimiaai/studio:certification38a1f0341982
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
altinity/metrics-exporter:0.20.01a46d104406d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
anchore/anchore-engine:v0.10.0bde9eedf639d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.3
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
andrianrf/backoffice:latest047a7837651e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
andrianrf/backoffice-be:latest6036614803d4
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
andrianrf/iso-server:latest7da47f525c7d
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
anguda/ant-media:2.5c435285fc241
nghttp2@1.40.0-1build1
no fix listed
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
nghttp2@1.64.0-1.1
no fix listed
1
anujdatar/cups:25.07.01685df04a643b
nghttp2@1.52.0-1+deb12u2
no fix listed
1
apache/activemq-artemis:2.44.00305c26f19ed
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
apache/activemq-artemis:2.37.0bae523439ee3
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
apache/airflow:2.8.4-python3.964e58748b6b9
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apache/camel-k:1.10.43bb13d14f64a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apache/hertzbeat:1.8.075d48a62748f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
apache/iotdb:0.13.3-nodeafa47bf1692a
nghttp2@1.40.0-1build1
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apache/polaris:lateste66366e783f1
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
nghttp2@1.40.0-1build1
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apachepulsar/pulsar:2.9.0d056c89b7131
nghttp2@1.40.0-1build1
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
nghttp2@1.40.0-1build1
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apache/rocketmq:5.3.0434d8398f996
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
apache/rocketmq-exporter:0.0.2c8fb51195444
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
apache/skywalking-oap-server:9.2.0133d35d2c263
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
nghttp2@1.40.0-1build1
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
apache/skywalking-ui:8.9.180530f0308a5
nghttp2@1.40.0-1build1
no fix listed
1
apache/superset:4.0.1ab9467fd712c
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
nghttp2@1.64.0-1.1
no fix listed
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.3
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.