StackRadar

CVE-2026-71554

Medium

Advisory

Published 6 Aug 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
59
deployed by those charts
Fix available
1 of 2
affected packages

h2: Duplicate Host header could facilitate request smuggling

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 59 images.

Affected packageAffected versionsFixed inImages
h2pypi2.6.2, 3.1.1, 4.0.0, 4.1.0+3 more4.4.159
python-h2deb4.1.0-4no fix listed1
OSV records
GHSA-6hr6-w5qg-qmwgUBUNTU-CVE-2026-71554
Also known as
PYSEC-2026-3628

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
h2@4.3.0
4.4.1

Open the chart page →

2,444
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
h2@4.3.0
4.4.1

Open the chart page →

11,950
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
h2@3.1.1
4.4.1

Open the chart page →

27,633
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
h2@4.3.0
4.4.1

Open the chart page →

4,749
prefect-agentprefectVerified publisher2024.8.301638221 of 1See more

prefect-agent prefect 2024.8.30163822

1 of the 1 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
h2@4.1.0
4.4.1

Open the chart page →

5,451
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
h2@4.1.0
4.4.1

Open the chart page →

21,211
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
h2@4.1.0
4.4.1

Open the chart page →

9,607
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
h2@4.2.0
4.4.1

Open the chart page →

3,312
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
h2@4.3.0
4.4.1

Open the chart page →

10,605
searxngrubxkubeVerified publisher0.1.01 of 2See more

searxng rubxkube 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
searxng/searxng:2026.7.28-c01178d035d6d903ab82a
h2@4.4.0
4.4.1

Open the chart page →

9
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
h2@4.1.0
4.4.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-71554.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
h2@4.1.0
4.4.1

Open the chart page →

1,636

Container images carrying it

59 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
h2@4.3.0
4.4.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
h2@4.1.0
4.4.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
h2@4.3.0
4.4.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
h2@4.3.0
4.4.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
h2@4.3.0
4.4.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
h2@4.1.0
4.4.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
h2@4.3.0
4.4.1
1
ghcr.io/radiorabe/catpage:2.2.17a37fc471447
h2@4.3.0
4.4.1
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
h2@4.4.0
4.4.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.