StackRadar

CVE-2026-56854

Unscored

Advisory

Published 28 Aug 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,911
of 17,805 indexed, latest versions
Container images
3,217
deployed by those charts
Fix available
1 of 1
affected package

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

Carried by container images the latest versions of 2,911 of 17,805 indexed charts deploy, on 3,217 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+156 more0.55.03,217
OSV records
GO-2026-6303

Charts affected

2,911 by stars
ChartLatestAffected imagesRadar Score
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.55.0

Open the chart page →

76,586
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.55.0

Open the chart page →

2,854
pulsarcloudve0.2.02 of 2See more

pulsar cloudve 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
golang.org/x/crypto@v0.33.0
0.55.0
library/docker:dind5efed980cba3
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

6,211
argo-cdcluster-deploy0.3.22 of 3See more

argo-cd cluster-deploy 0.3.2

2 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
golang.org/x/crypto@v0.53.0
0.55.0
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
golang.org/x/crypto@v0.49.0
0.55.0

Open the chart page →

3,826
argo-eventscluster-deploy0.1.01 of 1See more

argo-events cluster-deploy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
golang.org/x/crypto@v0.47.0
0.55.0

Open the chart page →

1,159
cert-managercluster-deploy0.2.24 of 4See more

cert-manager cluster-deploy 0.2.2

4 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.21.1ccf6b919ec05
golang.org/x/crypto@v0.53.0
0.55.0
quay.io/jetstack/cert-manager-controller:v1.21.1416a2d76870d
golang.org/x/crypto@v0.53.0
0.55.0
quay.io/jetstack/cert-manager-startupapicheck:v1.21.1d8ab6416e6e7
golang.org/x/crypto@v0.53.0
0.55.0
quay.io/jetstack/cert-manager-webhook:v1.21.1d8b3961b51c8
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

416
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
golang.org/x/crypto@v0.5.0
0.55.0

Open the chart page →

8,113
mla-external-secretscluster-deploy0.3.01 of 1See more

mla-external-secrets cluster-deploy 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
golang.org/x/crypto@v0.47.0
0.55.0

Open the chart page →

723
monitoringcluster-deploy0.3.09 of 11See more

monitoring cluster-deploy 0.3.0

9 of the 11 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/crypto@v0.47.0
0.55.0
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/crypto@v0.45.0
0.55.0
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/crypto@v0.45.0
0.55.0
prom/memcached-exporter:v0.15.592a6ad5a3d3e
golang.org/x/crypto@v0.45.0
0.55.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
golang.org/x/crypto@v0.47.0
0.55.0
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/crypto@v0.42.0
0.55.0
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/crypto@v0.47.0
0.55.0
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/crypto@v0.43.0
0.55.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/crypto@v0.46.0
0.55.0

Open the chart page →

8,293
traefikcluster-deploy0.3.01 of 1See more

traefik cluster-deploy 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
library/traefik:v3.7.109c3b91d5fb77
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

375
clusterfactoryclusterfactory0.2.02 of 5See more

clusterfactory clusterfactory 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
gitea/act_runner:0.3.1c2a169c5e998
golang.org/x/crypto@v0.48.0
0.55.0
jenkins/jenkins:2.541.3-jdk21c4098086090c
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

7,211
gitea-jenkinsclusterfactory0.1.12 of 5See more

gitea-jenkins clusterfactory 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
gitea/act_runner:latestb5c35d6bdbb9
golang.org/x/crypto@v0.48.0
0.55.0
jenkins/jenkins:2.541.3-jdk21c4098086090c
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

7,000
cluster-monitor-servercluster-monitor-server0.10.21 of 1See more

cluster-monitor-server cluster-monitor-server 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

753
clusternet-controller-managerclusternet1.0.01 of 1See more

clusternet-controller-manager clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-controller-manager:v1.0.02ce077d3d02d
golang.org/x/crypto@v0.40.0
0.55.0

Open the chart page →

1,554
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.55.0

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.55.0

Open the chart page →

2,203
door-agentcnoVerified publisher3.0.158 of 15See more

door-agent cno 3.0.15

8 of the 15 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/crypto@v0.36.0
0.55.0
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/crypto@v0.13.0
0.55.0
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/crypto@v0.0.0-20220314234659-1baeb1ce4c0b
0.55.0
doorcloud/apim-operator:v3.0.44e6ef8d72c3e
golang.org/x/crypto@v0.26.0
0.55.0
library/docker:27-cli851f91d24121
golang.org/x/crypto@v0.31.0
0.55.0
library/docker:27-dindaa3df78ecf32
golang.org/x/crypto@v0.27.0
0.55.0
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.55.0
quay.io/prometheus/prometheus:latest5ce7540c3c00
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

19,791
cohdicohdi0.2.21 of 3See more

cohdi cohdi 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
golang.org/x/crypto@v0.52.0
0.55.0

Open the chart page →

3,824
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.55.0

Open the chart page →

2,234
loki-stackcommon-chartsVerified publisher1.0.38 of 12See more

loki-stack common-charts 1.0.3

8 of the 12 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.0491b0578c049
golang.org/x/crypto@v0.53.0
0.55.0
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/crypto@v0.52.0
0.55.0
grafana/loki:3.6.1144148ad243c0
golang.org/x/crypto@v0.49.0
0.55.0
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/crypto@v0.42.0
0.55.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/crypto@v0.50.0
0.55.0
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
golang.org/x/crypto@v0.53.0
0.55.0
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/crypto@v0.54.0
0.55.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/crypto@v0.52.0
0.55.0

Open the chart page →

5,503
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

7,582
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.55.0

Open the chart page →

1,544
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

12,931
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
golang.org/x/crypto@v0.14.0
0.55.0

Open the chart page →

3,181
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

7,219
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

8,418
cert-manager-webhook-bluecatcontainerooVerified publisher1.0.21 of 1See more

cert-manager-webhook-bluecat containeroo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cert-manager-webhook-bluecat:latest96f82d5840d4
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

448
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.55.0

Open the chart page →

9,161
coordimap-agentcoordimap-agentVerified publisher0.4.31 of 1See more

coordimap-agent coordimap-agent 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
coordimap/coordimap-agent:latest7748fd0fae9f
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

769
cortezacorteza1.1.01 of 3See more

corteza corteza 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/crypto@v0.31.0
0.55.0

Open the chart page →

8,480
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/crypto@v0.19.0
0.55.0

Open the chart page →

4,702
ociscosmicrocks0.7.01 of 2See more

ocis cosmicrocks 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
owncloud/ocis:7.1.388e7c854517d
golang.org/x/crypto@v0.32.0
0.55.0

Open the chart page →

1,940
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
golang.org/x/crypto@v0.5.0
0.55.0

Open the chart page →

3,689
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
library/docker:dind5efed980cba3
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

14,826
cospacecospace0.0.341 of 3See more

cospace cospace 0.0.34

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/crypto@v0.48.0
0.55.0

Open the chart page →

2,308
katibcowboysysopVerified publisher2.4.22 of 4See more

katib cowboysysop 2.4.2

2 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.55.0
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.55.0

Open the chart page →

6,564
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/crypto@v0.0.0-20200728195943-123391ffb6de
0.55.0

Open the chart page →

3,837
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
golang.org/x/crypto@v0.40.0
0.55.0

Open the chart page →

1,871
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
golang.org/x/crypto@v0.14.0
0.55.0

Open the chart page →

6,871
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.55.0

Open the chart page →

2,577
notebook-controllercowboysysopVerified publisher1.1.21 of 1See more

notebook-controller cowboysysop 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.55.0

Open the chart page →

2,582
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.55.0

Open the chart page →

2,275
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.55.0

Open the chart page →

2,313
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.55.0

Open the chart page →

2,248
oam-kubernetes-runtime-legacycrossplane0.3.1-5.g11e18941 of 1See more

oam-kubernetes-runtime-legacy crossplane 0.3.1-5.g11e1894

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.55.0

Open the chart page →

2,232
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/crypto@v0.0.0-20190605123033-f99c8df09eb5
0.55.0

Open the chart page →

4,632
electric-mailcryptexlabsVerified publisher0.0.11 of 5See more

electric-mail cryptexlabs 0.0.1

1 of the 5 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.55.0

Open the chart page →

5,980
purple-piecryptexlabsVerified publisher0.0.11 of 4See more

purple-pie cryptexlabs 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.55.0

Open the chart page →

5,980
csghubcsghubVerified publisher2.5.013 of 34See more

csghub csghub 2.5.0

13 of the 34 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
golang.org/x/crypto@v0.47.0
0.55.0
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/crypto@v0.53.0
0.55.0
grafana/loki:3.4.258a6c186ce78
golang.org/x/crypto@v0.32.0
0.55.0
opencsghq/csghub-portal:v2.5.0-ee1cb36b49151e
golang.org/x/crypto@v0.26.0
0.55.0
opencsghq/csghub-server:v2.5.0-ee587046575c2c
golang.org/x/crypto@v0.54.0
0.55.0
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
golang.org/x/crypto@v0.37.0
0.55.0
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
golang.org/x/crypto@v0.28.0
0.55.0
opencsghq/gitlab-shell:v19.2.580a65ac370da
golang.org/x/crypto@v0.54.0
0.55.0
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
golang.org/x/crypto@v0.52.0
0.55.0
opencsghq/prometheus:v3.13.00aac0d04749e
golang.org/x/crypto@v0.52.0
0.55.0
opencsghq/prometheus-config-reloader:v0.92.144e6ec00729b
golang.org/x/crypto@v0.53.0
0.55.0
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
golang.org/x/crypto@v0.45.0
0.55.0
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
golang.org/x/crypto@v0.45.0
0.55.0

Open the chart page →

49,929
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
golang.org/x/crypto@v0.47.0
0.55.0
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

11,977

Container images carrying it

3,217 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.55.0
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/crypto@v0.4.0
0.55.0
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/crypto@v0.40.0
0.55.0
1
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/crypto@v0.32.0
0.55.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/crypto@v0.14.0
0.55.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/crypto@v0.14.0
0.55.0
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.55.0
1
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
golang.org/x/crypto@v0.33.0
0.55.0
1
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
golang.org/x/crypto@v0.31.0
0.55.0
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
golang.org/x/crypto@v0.6.0
0.55.0
1
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
golang.org/x/crypto@v0.19.0
0.55.0
1
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
golang.org/x/crypto@v0.36.0
0.55.0
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/crypto@v0.14.0
0.55.0
1
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
golang.org/x/crypto@v0.36.0
0.55.0
1
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
golang.org/x/crypto@v0.41.0
0.55.0
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
golang.org/x/crypto@v0.42.0
0.55.0
1
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
golang.org/x/crypto@v0.49.0
0.55.0
1
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
golang.org/x/crypto@v0.45.0
0.55.0
1
ghcr.io/glauth/glauth:v2.5.209c782ca5984
golang.org/x/crypto@v0.18.0
0.55.0
1
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
golang.org/x/crypto@v0.52.0
0.55.0
1
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
golang.org/x/crypto@v0.36.0
0.55.0
1
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
golang.org/x/crypto@v0.47.0
0.55.0
1
ghcr.io/googlecloudplatform/k8s-aibom05e86c39c535
golang.org/x/crypto@v0.52.0
0.55.0
1
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
golang.org/x/crypto@v0.29.0
0.55.0
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/crypto@v0.39.0
0.55.0
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
golang.org/x/crypto@v0.43.0
0.55.0
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
golang.org/x/crypto@v0.53.0
0.55.0
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
golang.org/x/crypto@v0.47.0
0.55.0
1
ghcr.io/grafana/grafana-operator:v5.18.00af2faec9d6f
golang.org/x/crypto@v0.36.0
0.55.0
1
ghcr.io/grafana/grafana-operator:v5.22.2d45fc24e8f43
golang.org/x/crypto@v0.48.0
0.55.0
1
ghcr.io/grycap/oscar:latest0c58ff972451
golang.org/x/crypto@v0.48.0
0.55.0
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
golang.org/x/crypto@v0.40.0
0.55.0
1
ghcr.io/haedalwang/kubescout:0.1.107d51f838f0d
golang.org/x/crypto@v0.46.0
0.55.0
1
ghcr.io/happymooguild/wardn-backend:0.1.023ee1b8cfc3c
golang.org/x/crypto@v0.54.0
0.55.0
1
ghcr.io/headlamp-k8s/headlamp:v0.43.05d03caa26df7
golang.org/x/crypto@v0.52.0
0.55.0
1
ghcr.io/helm/chartmuseum:v0.16.648bc27743c08
golang.org/x/crypto@v0.53.0
0.55.0
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/crypto@v0.9.0
0.55.0
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.55.0
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.55.0
1
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
golang.org/x/crypto@v0.36.0
0.55.0
1
ghcr.io/helmfile/helmfile:v1.7.4f20e612d5a98
golang.org/x/crypto@v0.24.0
0.55.0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
golang.org/x/crypto@v0.26.0
0.55.0
1
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
golang.org/x/crypto@v0.47.0
0.55.0
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
golang.org/x/crypto@v0.47.0
0.55.0
1
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
golang.org/x/crypto@v0.26.0
0.55.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
golang.org/x/crypto@v0.26.0
0.55.0
1
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
golang.org/x/crypto@v0.26.0
0.55.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.55.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.55.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
golang.org/x/crypto@v0.26.0
0.55.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.