StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,680
of 17,787 indexed, latest versions
Container images
1,610
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,680 of 17,787 indexed charts deploy, on 1,610 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,206
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more393
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,680 by stars
ChartLatestAffected imagesRadar Score
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,630
unboundschoolguys-helmcharts0.1.11 of 1See more

unbound schoolguys-helmcharts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
mvance/unbound:1.20.04bf67b567f39
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

2,748
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,570
pagessekharpkube1.0.02 of 3See more

pages sekharpkube 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

21,997
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,325
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

5,496
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,203
my-nginx-appsherif-nginx-app0.1.01 of 1See more

my-nginx-app sherif-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
shopwareshopware-storeVerified publisher2.1.11 of 5See more

shopware shopware-store 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
nghttp2@1.43.0-5.el9_3.1
0:1.43.0-6.el9_8.2

Open the chart page →

4,890
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.02 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
nghttp2@1.68.0-r1
1.70.0-r0
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

5,230
pagesshrutiujlan-pages1.0.02 of 3See more

pages shrutiujlan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

10,972
kubernetes-dashboard-gatewaysikalabs0.1.01 of 1See more

kubernetes-dashboard-gateway sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,443
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,857
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,948
simple-websimple-webVerified publisher1.1.11 of 1See more

simple-web simple-web 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
bitwardensinextraVerified publisher0.10.21 of 1See more

bitwarden sinextra 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,756
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,954
mongosyncsinextraVerified publisher0.4.01 of 1See more

mongosync sinextra 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,854
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

5,894
mimirskyloud-helm-chartsVerified publisher5.5.12 of 5See more

mimir skyloud-helm-charts 5.5.1

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

10,650
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

9,235
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,929
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

7,586
daemonsetsnowplow-devopsVerified publisher0.6.01 of 1See more

daemonset snowplow-devops 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
service-deploymentsnowplow-devopsVerified publisher0.43.01 of 1See more

service-deployment snowplow-devops 0.43.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:stablecb92301e719d
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,821
cost-analyzersoftonic2.5.52 of 6See more

cost-analyzer softonic 2.5.5

2 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

7,935
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2

Open the chart page →

3,042
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

13,653
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

13,127
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

30,759
nginx-chartsongduckbae-nginx0.1.01 of 1See more

nginx-chart songduckbae-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,839
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

11,243
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

3,272
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,853
speckle-preview-service-branch-testing6speckleVerified publisher2.23.14-branch.testing6.334655-b4e04ee1 of 1See more

speckle-preview-service-branch-testing6 speckle 2.23.14-branch.testing6.334655-b4e04ee

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,636
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

15,684
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

16,431
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

16,431
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

16,050
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

14,500
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,647
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,259
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

6,955
squadsquadVerified publisher0.1.111 of 1See more

squad squad 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cm2network/squad:latest8cba47f53df5
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

2,499
pagessrinipages1.0.02 of 3See more

pages srinipages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,233
servicexssl-hep1.8.510 of 16See more

servicex ssl-hep 1.8.5

10 of the 16 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex_app:v1.8.51d12f943cec5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
nghttp2@1.64.0-1.1+deb13u1
no fix listed
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

65,130
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

28,165

Container images carrying it

1,610 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
akeyless/base-rhel:0.0.14ba8900a0061
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
aktosecurity/data-ingestion-service213aded7adc5
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
nghttp2@1.68.0-2ubuntu0.1
1.68.0-2ubuntu0.2
1
alazidis/stornx:1.1.1602d4f7f090c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
nghttp2@1.52.0-1+deb12u2
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
nghttp2@1.30.0-1ubuntu1
no fix listed
1
alquimiaai/studio:certification38a1f0341982
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
altinity/metrics-exporter:0.20.01a46d104406d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
anchore/anchore-engine:v0.10.0bde9eedf639d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-6.el8_10.3
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
andrianrf/backoffice:latest047a7837651e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
andrianrf/backoffice-be:latest6036614803d4
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
andrianrf/iso-server:latest7da47f525c7d
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
1
anguda/ant-media:2.5c435285fc241
nghttp2@1.40.0-1build1
no fix listed
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
nghttp2@1.64.0-1.1
no fix listed
1
anujdatar/cups:25.07.01685df04a643b
nghttp2@1.52.0-1+deb12u2
no fix listed
1
apache/activemq-artemis:2.44.00305c26f19ed
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
apache/activemq-artemis:2.37.0bae523439ee3
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
apache/airflow:2.8.4-python3.964e58748b6b9
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apache/camel-k:1.10.43bb13d14f64a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apache/hertzbeat:1.8.075d48a62748f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
apache/iotdb:0.13.3-nodeafa47bf1692a
nghttp2@1.40.0-1build1
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apache/polaris:lateste66366e783f1
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
nghttp2@1.40.0-1build1
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apachepulsar/pulsar:2.9.0d056c89b7131
nghttp2@1.40.0-1build1
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
nghttp2@1.40.0-1build1
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
apache/rocketmq:5.3.0434d8398f996
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4
1
apache/rocketmq-exporter:0.0.2c8fb51195444
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
apache/skywalking-oap-server:9.2.0133d35d2c263
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
nghttp2@1.40.0-1build1
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
apache/skywalking-ui:8.9.180530f0308a5
nghttp2@1.40.0-1build1
no fix listed
1
apache/superset:4.0.1ab9467fd712c
nghttp2@1.52.0-1+deb12u1
no fix listed
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
nghttp2@1.64.0-1.1
no fix listed
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.3
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.