StackRadar

CVE-2026-56854

Unscored

Advisory

Published 28 Aug 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,945
of 17,821 indexed, latest versions
Container images
3,262
deployed by those charts
Fix available
1 of 1
affected package

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

Carried by container images the latest versions of 2,945 of 17,821 indexed charts deploy, on 3,262 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+157 more0.55.03,262
OSV records
GO-2026-6303

Charts affected

2,945 by stars
ChartLatestAffected imagesRadar Score
upcloud-csiupcloud-csiVerified publisher1.18.05 of 7See more

upcloud-csi upcloud-csi 1.18.0

5 of the 7 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/crypto@v0.51.0
0.55.0
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/crypto@v0.52.0
0.55.0
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/crypto@v0.47.0
0.55.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/crypto@v0.52.0
0.55.0
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/crypto@v0.52.0
0.55.0

Open the chart page →

1,924
kiamuswitch6.1.21 of 1See more

kiam uswitch 6.1.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/uswitch/kiam:v4.0be3a5846922d
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.55.0

Open the chart page →

2,973
proxyv2flyVerified publisher0.0.61 of 1See more

proxy v2fly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
v2fly/v2fly-core:latestd06727b221fe
golang.org/x/crypto@v0.43.0
0.55.0

Open the chart page →

1,436
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
golang.org/x/crypto@v0.47.0
0.55.0

Open the chart page →

730
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

1,267
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
0.55.0

Open the chart page →

5,517
devportalveecode-platform-nextVerified publisher0.1.231 of 1See more

devportal veecode-platform-next 0.1.23

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinneda72cf5cb47b8
golang.org/x/crypto@v0.46.0
0.55.0

Open the chart page →

1,852
velero-clientvelero-clientVerified publisher1.4.21 of 1See more

velero-client velero-client 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

548
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

7,521
verticadb-operatorvertica-chartsVerified publisher26.2.21 of 1See more

verticadb-operator vertica-charts 26.2.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
opentext/verticadb-operator:26.2.2-04ad44e44476c
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

82
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

7,539
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

7,441
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

7,441
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
golang.org/x/crypto@v0.1.0
0.55.0

Open the chart page →

4,443
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.55.0

Open the chart page →

69,387
vineyard-operatorvineyardVerified publisher0.24.22 of 2See more

vineyard-operator vineyard 0.24.2

2 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
golang.org/x/crypto@v0.21.0
0.55.0
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.55.0

Open the chart page →

4,576
ciliumvks-helm-chartsVerified publisher1.17.142 of 3See more

cilium vks-helm-charts 1.17.14

2 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
golang.org/x/crypto@v0.45.0
0.55.0
quay.io/cilium/operator-generic:v1.17.14773886ec9337
golang.org/x/crypto@v0.45.0
0.55.0

Open the chart page →

4,201
corednsvks-helm-chartsVerified publisher1.45.01 of 1See more

coredns vks-helm-charts 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
golang.org/x/crypto@v0.42.0
0.55.0

Open the chart page →

923
voidllmvoidllmVerified publisher0.0.251 of 1See more

voidllm voidllm 0.0.25

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/voidmind-io/voidllm:0.0.250df11dd20c28
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

291
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
golang.org/x/crypto@v0.0.0-20190927123631-a832865fa7ad
0.55.0

Open the chart page →

2,551
volcanovolcano-sh1.15.22 of 3See more

volcano volcano-sh 1.15.2

2 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.15.26a6bc2560d51
golang.org/x/crypto@v0.53.0
0.55.0
volcanosh/vc-webhook-manager:v1.15.22fff65aad011
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

1,542
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.55.0

Open the chart page →

2,508
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
golang.org/x/crypto@v0.49.0
0.55.0

Open the chart page →

4,088
gateway-control-planewallarmVerified publisher0.2.02 of 2See more

gateway-control-plane wallarm 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17c79fa5891443
golang.org/x/crypto@v0.32.0
0.55.0
wallarm/gateway-control-plane:0.2.0a321bc974a19
golang.org/x/crypto@v0.17.0
0.55.0

Open the chart page →

1,456
wallarm-node-nextwallarmVerified publisher0.5.32 of 2See more

wallarm-node-next wallarm 0.5.3

2 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
golang.org/x/crypto@v0.24.0
0.55.0
wallarm/node-next:0.5.24314f3d2b918
golang.org/x/crypto@v0.26.0
0.55.0

Open the chart page →

2,413
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
golang.org/x/crypto@v0.21.0
0.55.0

Open the chart page →

2,842
wardnwardnVerified publisher0.1.01 of 3See more

wardn wardn 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/happymooguild/wardn-backend:0.1.023ee1b8cfc3c
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

86
consulwarjiang1.3.02 of 2See more

consul warjiang 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/crypto@v0.14.0
0.55.0
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.55.0

Open the chart page →

4,102
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
golang.org/x/crypto@v0.31.0
0.55.0

Open the chart page →

5,142
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
golang.org/x/crypto@v0.14.0
0.55.0

Open the chart page →

1,692
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.55.0

Open the chart page →

5,623
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.55.0

Open the chart page →

11,209
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
golang.org/x/crypto@v0.5.0
0.55.0

Open the chart page →

6,302
azure-janitorwebdevopsVerified publisher1.0.131 of 1See more

azure-janitor webdevops 1.0.13

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
webdevops/azure-janitor:24.9.02446baee7b69
golang.org/x/crypto@v0.27.0
0.55.0

Open the chart page →

802
azure-keyvault-exporterwebdevopsVerified publisher1.0.121 of 1See more

azure-keyvault-exporter webdevops 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
webdevops/azure-keyvault-exporter:24.9.1f333704ecd60
golang.org/x/crypto@v0.27.0
0.55.0

Open the chart page →

801
azure-loganalytics-exporterwebdevopsVerified publisher1.0.131 of 1See more

azure-loganalytics-exporter webdevops 1.0.13

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
webdevops/azure-loganalytics-exporter:25.12.0051845d06d85
golang.org/x/crypto@v0.46.0
0.55.0

Open the chart page →

509
azure-resourcegraph-exporterwebdevopsVerified publisher1.1.51 of 1See more

azure-resourcegraph-exporter webdevops 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
webdevops/azure-resourcegraph-exporter:24.9.0381136dda026
golang.org/x/crypto@v0.27.0
0.55.0

Open the chart page →

786
azure-resourcemanager-exporterwebdevopsVerified publisher1.3.61 of 1See more

azure-resourcemanager-exporter webdevops 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
webdevops/azure-resourcemanager-exporter:26.1.0d3e1842ad419
golang.org/x/crypto@v0.46.0
0.55.0

Open the chart page →

536
pagerduty-exporterwebdevopsVerified publisher1.1.81 of 1See more

pagerduty-exporter webdevops 1.1.8

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
webdevops/pagerduty-exporter:25.12.183b95faf10a0
golang.org/x/crypto@v0.46.0
0.55.0

Open the chart page →

509
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

2,549
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
golang.org/x/crypto@v0.25.0
0.55.0

Open the chart page →

28,827
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.55.0

Open the chart page →

7,563
ambassadorwener6.9.51 of 2See more

ambassador wener 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.55.0

Open the chart page →

4,130
apisixwener2.17.01 of 3See more

apisix wener 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

3,187
argo-cdwener10.9.22 of 3See more

argo-cd wener 10.9.2

2 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/crypto@v0.47.0
0.55.0
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

3,043
argocd-image-updaterwener1.3.11 of 1See more

argocd-image-updater wener 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

733
argo-eventswener2.4.271 of 1See more

argo-events wener 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
golang.org/x/crypto@v0.45.0
0.55.0

Open the chart page →

1,093
argo-rolloutswener2.43.21 of 1See more

argo-rollouts wener 2.43.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-rollouts:v1.10.0187630ba7228
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

122
athens-proxywener0.5.22 of 2See more

athens-proxy wener 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/crypto@v0.0.0-20191206172530-e9b2fee46413
0.55.0
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/crypto@v0.45.0
0.55.0

Open the chart page →

5,009
cadencewener0.23.01 of 5See more

cadence wener 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.55.0

Open the chart page →

10,152

Container images carrying it

3,262 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/metrics-server/metrics-server:v0.7.01c0419326500
golang.org/x/crypto@v0.18.0
0.55.0
1
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/crypto@v0.18.0
0.55.0
1
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
golang.org/x/crypto@v0.23.0
0.55.0
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/crypto@v0.25.0
0.55.0
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
golang.org/x/crypto@v0.46.0
0.55.0
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/crypto@v0.1.0
0.55.0
1
registry.k8s.io/provider-os/openstack-cloud-controller-manager:v1.36.0e354e40db2d0
golang.org/x/crypto@v0.50.0
0.55.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/crypto@v0.38.0
0.55.0
1
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/crypto@v0.37.0
0.55.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/crypto@v0.36.0
0.55.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
golang.org/x/crypto@v0.53.0
0.55.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.55.0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.