StackRadar

CVE-2026-56853

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,578
of 17,821 indexed, latest versions
Container images
5,291
deployed by those charts
Fix available
1 of 2
affected packages

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

Carried by container images the latest versions of 4,578 of 17,821 indexed charts deploy, on 5,291 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.135,291
OSV records
DEBIAN-CVE-2026-56853GO-2026-6089
Also known as
BIT-golang-2026-56853

Charts affected

4,578 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

5,291 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.25.13
2
hashicorp/vault-k8s:1.3.15d74a885ae3e
stdlib@go1.21.3
1.25.13
2
hashicorp/vault-k8s:1.1.0844337076b72
stdlib@go1.19.3
1.25.13
2
hashicorp/vault-k8s:0.13.1bebb03e8e800
stdlib@go1.16.3
1.25.13
2
helmforge/kubectl:1.35.3c3f97e954c47
stdlib@go1.25.7
1.25.13
2
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.25.13
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
stdlib@go1.21.10
1.25.13
2
ilum/api:6.7.3624fd09528c8
stdlib@go1.23.7
1.25.13
2
ilum/mongodb:6.0.542b6d774c37d
stdlib@go1.20.12
1.25.13
2
inaccel/daemon:latest093e1ea90ab8
stdlib@go1.21.6
1.25.13
2
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.25.13
2
inaccel/reef:latestc967218739f3
stdlib@go1.21.6
1.25.13
2
infisical/infisical:latest:v0.165.602082bf13163
stdlib@go1.25.12
1.25.13
2
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
stdlib@go1.17.3
1.25.13
2
iomesh/csi-provisioner:v3.0.0f9508460b273
stdlib@go1.16.2
1.25.13
2
iomesh/csi-snapshotter:v6.2.2becc53e25b96
stdlib@go1.19
1.25.13
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
stdlib@go1.13.1
1.25.13
2
iomesh/livenessprobe:v2.8.0560f01510f99
stdlib@go1.18
1.25.13
2
iomesh/localpv-manager:v0.2.0f13deacac3f4
stdlib@go1.20.3
1.25.13
2
iomesh/node-disk-exporter:1.8.0f03148764f38
stdlib@go1.14.7
1.25.13
2
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
stdlib@go1.19
1.25.13
2
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
stdlib@go1.19.7
1.25.13
2
ipfs/ipfs-cluster:latest:v1.1.6a83266c524f1
stdlib@go1.26.3
1.25.13
2
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.13
2
istio/install-cni:1.24.2-distrolessaef4825e110f
stdlib@go1.23.2
1.25.13
2
istio/pilot:1.24.2-distroless137e44e3d1d2
stdlib@go1.23.2
1.25.13
2
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.25.13
2
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.13
2
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.25.13
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
stdlib@go1.20.6
1.25.13
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
stdlib@go1.25.3
1.25.13
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
stdlib@go1.13.11
1.25.13
2
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
stdlib@go1.15.3
1.25.13
2
jmalloc/echo-server:0.3.1e4eaee2c7998
stdlib@go1.17
1.25.13
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
stdlib@go1.19.4
1.25.13
2
kbudde/rabbitmq-exporter:1.0.0:latest12f27d6d84e6
stdlib@go1.21.8
1.25.13
2
kong/kubernetes-ingress-controller:3.5979f12864a13
stdlib@go1.25.12
1.25.13
2
kubernetesui/dashboard:v2.2.0148991563e37
stdlib@go1.15.1
1.25.13
2
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
stdlib@go1.16.9
1.25.13
2
l7mp/stunner-auth-server:1.2.10d2094060b72
stdlib@go1.26.4
1.25.13
2
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
2
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
stdlib@go1.19.3
1.25.13
2
langgenius/dify-sandbox:0.2.009b7e8705673
stdlib@go1.20.6
1.25.13
2
library/arangodb:3.11.81e75d74954a4
stdlib@go1.21.5
1.25.13
2
library/caddy:2.11.4-alpine:2-alpinede23def33b17
stdlib@go1.26.3
1.25.13
2
library/caddy:latestdf7f1c2fb114
stdlib@go1.26.3
1.25.13
2
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.25.13
2
library/ghost:6.64.0a31d03f1f629
stdlib@go1.26.4
1.25.13
2
library/influxdb:2.6.1-alpine44a366dd7724
stdlib@go1.19.4
1.25.13
2

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.