StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,663
of 17,787 indexed, latest versions
Container images
1,591
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,663 of 17,787 indexed charts deploy, on 1,591 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,188
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more392
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,663 by stars
ChartLatestAffected imagesRadar Score
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,607
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

12,949
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

68,240
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

4,928
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed

Open the chart page →

32,902
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,909
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
no fix listed
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

27,550
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

19,224
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,190
adventurelogdjjudas21Verified publisher0.1.12 of 3See more

adventurelog djjudas21 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
nghttp2@1.64.0-1.1+deb13u1
no fix listed
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
nghttp2@1.69.0-r0
1.70.0-r0

Open the chart page →

7,459
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
nghttp2@1.52.0-1
no fix listed

Open the chart page →

7,141
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

16,954
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,174
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,966
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nghttp2@1.52.0-1
no fix listed

Open the chart page →

14,627
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,822
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,822
dnation-kubernetes-monitoring-stackdnationcloud4.0.23 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

3 of the 17 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

21,641
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

8,986
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,270
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

3,167
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

24,917
healthchecksdoubanVerified publisher1.0.101 of 2See more

healthchecks douban 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
healthchecks/healthchecks:latestaa08a61b0dcf
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,709
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

11,782
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
no fix listed
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

24,656
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-6.el9_8.2
quay.io/keycloak/keycloak:20.0054ef67eb7da
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
ghcr.io/ctron/kubectl:1.25e37d61b5277c
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,915
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,460
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,455
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

19,802
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,244
base-consensusdysnixVerified publisher0.2.01 of 1See more

base-consensus dysnix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4

Open the chart page →

1,695
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

13,391
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

11,482
orion-ldeclipse-aeriosVerified publisher1.0.02 of 2See more

orion-ld eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fiware/orion-ld:1.10.03c490a746f65
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
library/mongo:7.0.12ae1cf99fa7bf
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

9,764
redpandaeclipse-aeriosVerified publisher5.7.81 of 4See more

redpanda eclipse-aerios 5.7.8

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
redpandadata/redpanda:latest468bd13a9f2b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,573
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

10,981
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,190
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

5,112
vaultwardenedudip0.11.01 of 1See more

vaultwarden edudip 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,035
esphomeegebackVerified publisher2.0.251 of 1See more

esphome egeback 2.0.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
esphome/esphome:2026.7.44866347cb5b4
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,121
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

7,268
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

30,159
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,033
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

8,041

Container images carrying it

1,591 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
archivebox/archivebox:0.7.41a5a37331091
nghttp2@1.52.0-1+deb12u3
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
nghttp2@1.52.0-1+deb12u1
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
nghttp2@1.40.0-1ubuntu0.1
no fix listed
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
no fix listed
1
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
assistiot/open_api_backend:1.1.230812ba93555
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
no fix listed
1
atlassian/confluence-server:7.10.03b9222ab32ef
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
atlassian/jira-software:8.14.037bc46cbec1a
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
1
atlassian/jira-software:9.7.264a75aa4ec4e
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
avinash263/pyredis263:latestaa2b8727f1a6
nghttp2@1.52.0-1
no fix listed
1
avzini/web-app:latestf40b30210ed0
nghttp2@1.52.0-1
no fix listed
1
baserow/backend:2.3.37c00549b3a6f
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
nghttp2@1.52.0-1+deb12u2
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
nghttp2@1.40.0-1build1
no fix listed
1
beopenit/door-helm:v3.0.1b4d9f9bee224
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
nghttp2@1.64.0-1.1
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/git:latest4b08d0c5af8d
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
nghttp2@1.52.0-1+deb12u1
no fix listed
1
bitnamilegacy/mongodb:latestb0652af9c8d0
nghttp2@1.52.0-1+deb12u2
no fix listed
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
nghttp2@1.52.0-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.