StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,663
of 17,787 indexed, latest versions
Container images
1,591
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,663 of 17,787 indexed charts deploy, on 1,591 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,188
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more392
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,663 by stars
ChartLatestAffected imagesRadar Score
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

9,620
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4

Open the chart page →

5,604
aapm-servicekron-pam-aapm-helmcharts1.2.51 of 1See more

aapm-service kron-pam-aapm-helmcharts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
krontechnology/aapm-service:1.1.39dd602db8baa
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

2,606
kron-aapm-agentkron-pam-aapm-helmcharts1.2.51 of 1See more

kron-aapm-agent kron-pam-aapm-helmcharts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.8.41cc7d5be6529
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

2,707
web-chartktcloudhelm0.1.01 of 1See more

web-chart ktcloudhelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827
web-chartktcloudlab0.1.01 of 1See more

web-chart ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827
web-chartktcloudlabstudent0.1.01 of 1See more

web-chart ktcloudlabstudent 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827
web-chartktcloudljw0.1.01 of 1See more

web-chart ktcloudljw 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827
authorino-operatorkuadrantOfficialVerified publisher0.26.01 of 1See more

authorino-operator kuadrant 0.26.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/kuadrant/authorino-operator:v0.26.003b2acc469f4
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

219
kubeadapt-k8s-pulsekubeadaptVerified publisher1.0.11 of 1See more

kubeadapt-k8s-pulse kubeadapt 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

2,409
fabric-operatorkubebb0.1.01 of 1See more

fabric-operator kubebb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

3,988
miniokubebb5.0.102 of 2See more

minio kubebb 5.0.10

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

7,459
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

8,405
smartfs-csi-driverkubeblocksVerified publisher0.1.21 of 6See more

smartfs-csi-driver kubeblocks 0.1.2

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
nghttp2@1.33.0-5.el8_8
0:1.33.0-6.el8_10.3

Open the chart page →

9,249
listener-operatorkubedoopVerified publisher0.4.01 of 6See more

listener-operator kubedoop 0.4.0

1 of the 6 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

4,373
secret-operatorkubedoopVerified publisher0.4.01 of 5See more

secret-operator kubedoop 0.4.0

1 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

4,341
kubemacpoolkubemacpoolVerified publisher0.3.01 of 1See more

kubemacpool kubemacpool 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
nghttp2@1.43.0-6.el9
0:1.43.0-6.el9_8.2

Open the chart page →

1,607
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,157
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

4,940
firefly-iiikubernetes-homelab-helm-chartsVerified publisher0.1.31 of 3See more

firefly-iii kubernetes-homelab-helm-charts 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.6.6ae69fdd95cde
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,382
flaresolverrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

flaresolverr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

33,583
scrutinykubernetes-homelab-helm-chartsVerified publisher0.2.22 of 3See more

scrutiny kubernetes-homelab-helm-charts 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/influxdb:2.8571eb4514977
nghttp2@1.52.0-1+deb12u3
no fix listed
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

5,500
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

6,356
vaultwardenkubernetes-homelab-helm-chartsVerified publisher0.1.11 of 1See more

vaultwarden kubernetes-homelab-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,035
kubernetes-kiosk-chromiumkubernetes-kiosk-chromium0.1.21 of 1See more

kubernetes-kiosk-chromium kubernetes-kiosk-chromium 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

28,843
kubernetes-nmstatekubernetes-nmstateVerified publisher0.87.01 of 1See more

kubernetes-nmstate kubernetes-nmstate 0.87.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/nmstate/kubernetes-nmstate-operator:v0.87.04dce694f01ea
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

354
brudi-operatorkubernetes-replicator0.2.31 of 1See more

brudi-operator kubernetes-replicator 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

3,622
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

14,320
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/mongo:4.2.16ca49afbcb2b
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

9,623
mysqlkubesphere-testVerified publisher1.0.21 of 3See more

mysql kubesphere-test 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,342
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,342
forkliftkubevirt-forkliftVerified publisher0.3.01 of 2See more

forklift kubevirt-forklift 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/kubev2v/forklift-operator:release-2.1268657c36c086
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

1,417
network-enforcerkubewardenVerified publisher0.1.21 of 3See more

network-enforcer kubewarden 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0.4ca08b7d2df5b
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

2,545
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

8,698
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
penpotapp/exporter:2.2.15c835ffd87ab
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

16,877
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
nghttp2@1.64.0-1.1
no fix listed
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

20,204
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

6,824
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

3,104
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

3,334
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

16,520
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

7,802
strimzi-kafka-operatorkvalitetsitVerified publisher0.36.11 of 1See more

strimzi-kafka-operator kvalitetsit 0.36.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.36.1e9e03b31007c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

4,098
nginx-chartkyb-nginx0.1.01 of 1See more

nginx-chart kyb-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

26,356
pageslatif-pages1.0.02 of 3See more

pages latif-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,190
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

20,190
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

33,242
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,423
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

4,232
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,035

Container images carrying it

1,591 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/nginx:1.31:1.31.5:latest:trixie05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed
106
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
79
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed
79
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed
23
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed
13
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
10
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
no fix listed
10
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
8
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
7
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
vaultwarden/server:1.37.2:latest094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed
7
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
7
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
no fix listed
6
library/wordpress:7.1.0-apache:latest5a93c470ae82
nghttp2@1.64.0-1.1+deb13u1
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
nghttp2@1.52.0-1+deb12u1
no fix listed
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
nghttp2@1.52.0-1+deb12u3
no fix listed
5
library/httpd:2.4:2.4.68:latest979c38c2228d
nghttp2@1.64.0-1.1+deb13u1
no fix listed
5
library/mongo:4.44be76f674fc4
nghttp2@1.40.0-1ubuntu0.3
no fix listed
5
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
nghttp2@1.52.0-1+deb12u2
no fix listed
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
4
library/mongo:5.0-focal5e15a3f014ed
nghttp2@1.40.0-1ubuntu0.3
no fix listed
4
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
no fix listed
4
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
no fix listed
4
library/nginx:1.27.1287ff321f9e3
nghttp2@1.52.0-1+deb12u1
no fix listed
4
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
4
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
4
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
no fix listed
4
rancher/rancher:v2.15.15f6c4dc52a05
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1
4
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
4
apache/superset:6.1.0:latest16b50bbef664
nghttp2@1.52.0-1+deb12u3
no fix listed
3
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
no fix listed
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
no fix listed
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
no fix listed
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3
3
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
3
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
no fix listed
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed
3
fluent/fluent-bit:5.1.2:latestd792375ca8e5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
3
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
3
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
nghttp2@1.52.0-1+deb12u1
no fix listed
3
library/node:ltsbe23f54a88d3
nghttp2@1.52.0-1+deb12u3
no fix listed
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
3
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
no fix listed
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.