StackRadar

CVE-2026-58055

Medium

Advisory

Published 28 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,677
of 17,781 indexed, latest versions
Container images
1,606
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nghttp2 security update

Carried by container images the latest versions of 1,677 of 17,781 indexed charts deploy, on 1,606 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.40.0-1ubuntu0.2+20 more1.43.0-1ubuntu0.4, 1.59.0-1ubuntu0.4, 1.64.0-1.1+e2, 1.64.0-1.1ubuntu1.2+1 more1,203
nghttp2apk1.63.0-r0, 1.64.0-r1, 1.66.0-r1, 1.68.0-r0+2 more1.70.0-r011
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+18 more0:1.33.0-6.el8_10.3, 0:1.43.0-6.el9_8.2, 0:1.68.0-3.el10_2.2, 1.64.0-150700.3.6.1+2 more392
OSV records
CGA-43r8-f2xj-r388CGA-7g67-8qrj-cr3qDEBIAN-CVE-2026-58055RHSA-2026:54650RHSA-2026:54662RHSA-2026:55804RLSA-2026:54650RLSA-2026:54662RLSA-2026:55804UBUNTU-CVE-2026-58055ECHO-401a-73df-0d29openSUSE-SU-2026:11156-1SUSE-SU-2026:22630-1SUSE-SU-2026:4029-1
Also known as
CGA-8pjw-3mvg-2x6m, CGA-mrwp-fgwh-65q5, USN-8495-1

Charts affected

1,677 by stars
ChartLatestAffected imagesRadar Score
kimai2robjuz5.0.131 of 2See more

kimai2 robjuz 5.0.13

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kimai/kimai2:2.65.06dfc63199654
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,693
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

6,045
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

7,740
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

6,879
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

7,529
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
no fix listed

Open the chart page →

12,930
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,315
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

13,541
kyoorubxkubeVerified publisher0.1.103 of 9See more

kyoo rubxkube 0.1.10

3 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
nghttp2@1.52.0-1+deb12u2
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

30,234
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

38,107
immichsecustorVerified publisher2.0.41 of 1See more

immich secustor 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

3,059
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
nghttp2@1.33.0-6.el8_10.1
0:1.33.0-6.el8_10.3
ghcr.io/getsentry/snuba:26.7.210f8d164109b
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

16,449
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
nghttp2@1.52.0-1+deb12u2
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

11,532
sigscale-csesigscale-cseOfficialVerified publisher1.4.221 of 1See more

sigscale-cse sigscale-cse 1.4.22

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sigscale/cse:latest67d0c886516b
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,280
sigscale-ocssigscale-ocsOfficialVerified publisher1.1.171 of 1See more

sigscale-ocs sigscale-ocs 1.1.17

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sigscale/ocs:latest3c1bdc9732e2
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

2,280
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

4,238
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,913
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
altinity/metrics-exporter:0.20.01a46d104406d
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

6,422
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
nghttp2@1.40.0-1build1
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

45,832
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,126
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.41 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

4,563
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
nghttp2@1.52.0-1+deb12u1
no fix listed

Open the chart page →

5,676
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

10,380
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3

Open the chart page →

11,459
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

24,930
stornxstornxVerified publisher1.1.12 of 9See more

stornx stornx 1.1.1

2 of the 9 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
nghttp2@1.52.0-1+deb12u2
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

11,574
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

2,826
strimzi-drain-cleanerstrimzi1.6.11 of 1See more

strimzi-drain-cleaner strimzi 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

502
strimzi-drain-cleanerstrimzi-drain-cleaner1.6.11 of 1See more

strimzi-drain-cleaner strimzi-drain-cleaner 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2

Open the chart page →

502
supabasesupabse0.8.02 of 11See more

supabase supabse 0.8.0

2 of the 11 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
supabase/realtime:v2.102.3aa1c92c0cf32
nghttp2@1.52.0-1+deb12u3
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
nghttp2@1.52.0-1+deb12u3
no fix listed

Open the chart page →

18,075
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

3,240
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

1,827
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
nghttp2@1.64.0-1.1+deb13u1+dhi2
no fix listed

Open the chart page →

2,522
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
no fix listed

Open the chart page →

9,102
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
no fix listed

Open the chart page →

9,102
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
nghttp2@1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.4

Open the chart page →

4,020
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
nghttp2@1.64.0-1.1+deb13u1
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

5,338
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,764
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4

Open the chart page →

3,764
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

12,581
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

2,251
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4

Open the chart page →

4,010
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
nghttp2@1.52.0-1+deb12u2
no fix listed

Open the chart page →

5,225
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
nghttp2@1.40.0-1ubuntu0.1
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
no fix listed

Open the chart page →

26,657
waldurwaldur-chartsVerified publisher8.1.21 of 3See more

waldur waldur-charts 8.1.2

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
opennode/waldur-mastermind:8.1.24c82b15d9042
nghttp2@1.64.0-1.1+deb13u1
no fix listed

Open the chart page →

4,839
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
nghttp2@1.30.0-1ubuntu1
no fix listed

Open the chart page →

15,970
cockroachdbwenerme22.0.31 of 3See more

cockroachdb wenerme 22.0.3

1 of the 3 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3

Open the chart page →

744
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
nghttp2@1.40.0-1ubuntu0.3
no fix listed

Open the chart page →

7,835
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-58055.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
nghttp2@1.64.0-1.1
no fix listed

Open the chart page →

7,696

Container images carrying it

1,606 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/nginx:1.31:1.31.5:latest:trixie05b8cb60c354
nghttp2@1.64.0-1.1+deb13u1
no fix listed
106
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
no fix listed
79
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
no fix listed
79
library/nginx:stabled5792f71a949
nghttp2@1.64.0-1.1+deb13u1
no fix listed
23
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
nghttp2@1.64.0-1.1+deb13u1
no fix listed
13
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
10
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
no fix listed
10
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
8
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
library/kong:3.6a42d2b4503e7
nghttp2@1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.4
7
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
vaultwarden/server:1.37.2:latest094b5689ed81
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
nghttp2@1.52.0-1+deb12u3
no fix listed
7
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
nghttp2@1.64.0-1.1+deb13u1
no fix listed
7
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
nghttp2@1.43.0-6.el9_8.1
0:1.43.0-6.el9_8.2
7
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
nghttp2@1.52.0-1+deb12u2
no fix listed
6
library/wordpress:7.1.0-apache:latest5a93c470ae82
nghttp2@1.64.0-1.1+deb13u1
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
no fix listed
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
nghttp2@1.52.0-1+deb12u1
no fix listed
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
nghttp2@1.52.0-1+deb12u3
no fix listed
5
library/httpd:2.4:2.4.68:latest979c38c2228d
nghttp2@1.64.0-1.1+deb13u1
no fix listed
5
library/mongo:4.44be76f674fc4
nghttp2@1.40.0-1ubuntu0.3
no fix listed
5
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
nghttp2@1.52.0-1+deb12u2
no fix listed
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
nghttp2@1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.4
4
library/mongo:5.0-focal5e15a3f014ed
nghttp2@1.40.0-1ubuntu0.3
no fix listed
4
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
no fix listed
4
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
no fix listed
4
library/nginx:1.27.1287ff321f9e3
nghttp2@1.52.0-1+deb12u1
no fix listed
4
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
4
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
4
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
no fix listed
4
rancher/rancher:v2.15.15f6c4dc52a05
nghttp2@1.64.0-150700.3.3.1
1.64.0-150700.3.6.1
4
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
4
apache/superset:6.1.0:latest16b50bbef664
nghttp2@1.52.0-1+deb12u3
no fix listed
3
bitnamilegacy/kubectl:latestcd354d5b2556
nghttp2@1.52.0-1+deb12u2
no fix listed
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
nghttp2@1.52.0-1+deb12u2
no fix listed
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
no fix listed
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
nghttp2@1.33.0-6.el8_10.2
0:1.33.0-6.el8_10.3
3
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.4
3
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
no fix listed
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
nghttp2@1.52.0-1+deb12u3
no fix listed
3
fluent/fluent-bit:5.1.2:latestd792375ca8e5
nghttp2@1.64.0-1.1+deb13u1
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
3
guacamole/guacamole:1.6.0f344085e618b
nghttp2@1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.4
3
jacobalberty/unifi:v10.0.162896c0ab82d33
nghttp2@1.40.0-1ubuntu0.3
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
nghttp2@1.52.0-1+deb12u1
no fix listed
3
library/node:ltsbe23f54a88d3
nghttp2@1.52.0-1+deb12u3
no fix listed
3
localstack/localstack-pro:latest4aef81c53168
nghttp2@1.64.0-1.1+deb13u1
no fix listed
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-6.el8_10.3
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.