StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,663
of 17,787 indexed, latest versions
Container images
1,591
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,663 of 17,787 indexed charts deploy, on 1,591 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,188
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more392
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,663 by stars
ChartLatestAffected imagesRadar Score
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,592
aceappscodeVerified publisher2026.9.111 of 2See more

ace appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,894
ace-installerappscodeVerified publisher2026.9.111 of 2See more

ace-installer appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,225
ace-installer-certifiedappscodeVerified publisher2026.9.111 of 2See more

ace-installer-certified appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

3,225
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,592
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

621
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

621
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,038
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,963
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:latest536358d7b17e
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

16,975
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,404
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

894
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,592
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,043
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3

Open the chart page →

2,569
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

37,268
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,270
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
no fix listed

Open the chart page →

5,657
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-6.el8_10.3

Open the chart page →

2,903
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,489
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

7,300
arlas-aiasarlas-stackVerified publisher28.8.07 of 22See more

arlas-aias arlas-stack 28.8.0

7 of the 22 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
nghttp2@1.52.0-1+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

40,238
titilerarlas-stackVerified publisher28.8.01 of 1See more

titiler arlas-stack 28.8.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,445
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

23,353
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

3,530
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
no fix listed
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

22,568
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

14,728
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

9,369
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

13,352
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

10,061
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4

Open the chart page →

18,277
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

8,032
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

7,936
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

5,363
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
no fix listed
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

45,363
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
no fix listed
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

13,913
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

32,501
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,412
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

6,908
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
nghttp2@1.52.0-1
no fix listed

Open the chart page →

6,297
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

7,152
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
nghttp2@1.52.0-1+deb12u2
no fix listed
kuzwolka/aws9:news3e8880fbbb96
nghttp2@1.52.0-1+deb12u2
no fix listed
kuzwolka/aws9:blog4a7707410bf1
nghttp2@1.52.0-1+deb12u2
no fix listed
kuzwolka/aws9:shop84a9d9766345
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

18,344
aws-web-service-proxifiedaws-web-service-proxified1.8.01 of 2See more

aws-web-service-proxified aws-web-service-proxified 1.8.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,009
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,268
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
infiniflow/infinity:v0.7.0992c87a68612
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

5,823
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

2,738
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
nghttp2@1.52.0-1
no fix listed

Open the chart page →

6,297
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
nghttp2@1.40.0-1build1
no fix listed
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
nghttp2@1.40.0-1build1
no fix listed
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

20,671
my-nginx-appbassant-nginx-app0.1.01 of 1See more

my-nginx-app bassant-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827

Container images carrying it

1,591 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-kafka:7.6.683dbca3efd2a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
nghttp2@1.33.0-5.el8_9
0:1.33.0-6.el8_10.3
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
consensys/teku:25.4.1bf6ecd2ea716
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
nghttp2@1.52.0-1+deb12u1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
cortezaproject/corteza:2024.9.08eb7a26605c9
nghttp2@1.40.0-1ubuntu0.3
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
nghttp2@1.52.0-1+deb12u2
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
nghttp2@1.64.0-1.1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
nghttp2@1.40.0-1build1
no fix listed
1
craftypath/sops-operator:v0.8.0402a0024c732
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
cribl/cribl:3.0.2762747cb6796
nghttp2@1.30.0-1ubuntu1
no fix listed
1
cspconsole/config-provider:1.0.365524a26a6c23
nghttp2@1.52.0-1+deb12u2
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
nghttp2@1.52.0-1+deb12u2
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
nghttp2@1.52.0-1+deb12u2
no fix listed
1
ctron/hawkbit-operator:0.1.48fdea8f76499
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
nghttp2@1.64.0-1.1
no fix listed
1
cznic/knot-resolver:v6.4.2fe71c5214fdc
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
nghttp2@1.52.0-1
no fix listed
1
dannielkil/book-frontend:latest937993927694
nghttp2@1.52.0-1+deb12u1
no fix listed
1
daskdev/dask-notebook:1.1.0052630f5ca04
nghttp2@1.30.0-1ubuntu1
no fix listed
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
datamate/seafile-professional:11.0.202dd66b722464
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
nghttp2@1.59.0-1ubuntu0.3
1.59.0-1ubuntu0.4
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
1
deconzcommunity/deconz:2.29.2062de2362641
nghttp2@1.52.0-1+deb12u2
no fix listed
1
dellcloud/category:distributed02fc234353a9
nghttp2@1.40.0-1build1
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
nghttp2@1.40.0-1build1
no fix listed
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
nghttp2@1.64.0-1.1
no fix listed
1
dependencytrack/apiserver:latestf1da63ed610a
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
dessalines/lemmy:0.19.2079e9f02c286c
nghttp2@1.52.0-1+deb12u3
no fix listed
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
nghttp2@1.40.0-1build1
no fix listed
1
diygod/rsshub:latest1d4b508b6357
nghttp2@1.64.0-1.1+deb13u1
no fix listed
1
diygod/rsshub:2025-11-097a6312cac0d5
nghttp2@1.52.0-1+deb12u2
no fix listed
1
dniel/api-posts:master45a667852f2a
nghttp2@1.30.0-1ubuntu1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.