StackRadar

CVE-2026-56855

Unscored

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,012
of 17,797 indexed, latest versions
Container images
3,391
deployed by those charts
Fix available
1 of 1
affected package

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Carried by container images the latest versions of 3,012 of 17,797 indexed charts deploy, on 3,391 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+157 more0.56.03,391
OSV records
GO-2026-6355
Trending
Rank 40 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

3,012 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/crypto@v0.7.0
0.56.0

Open the chart page →

7,714
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/crypto@v0.7.0
0.56.0

Open the chart page →

1,998
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/crypto@v0.13.0
0.56.0

Open the chart page →

1,955
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
golang.org/x/crypto@v0.54.0
0.56.0
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/crypto@v0.5.0
0.56.0

Open the chart page →

13,813
ygdrassil-monitoringygdrassilVerified publisher0.4.07 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

7 of the 10 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
golang.org/x/crypto@v0.32.0
0.56.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/crypto@v0.31.0
0.56.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/crypto@v0.31.0
0.56.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.56.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/crypto@v0.31.0
0.56.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/crypto@v0.32.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.56.0

Open the chart page →

9,401
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
golang.org/x/crypto@v0.22.0
0.56.0

Open the chart page →

1,610
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/crypto@v0.0.0-20211115234514-b4de73f9ece8
0.56.0

Open the chart page →

1,965
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.56.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.56.0

Open the chart page →

8,000
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0

Open the chart page →

3,024
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
golang.org/x/crypto@v0.52.0
0.56.0
quay.io/prometheus/alertmanager:latest690c7b525f43
golang.org/x/crypto@v0.54.0
0.56.0
quay.io/prometheus/prometheus:latest5ce7540c3c00
golang.org/x/crypto@v0.54.0
0.56.0

Open the chart page →

899
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.56.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.56.0

Open the chart page →

5,047
zahori-moonzahoriVerified publisher1.0.11 of 3See more

zahori-moon zahori 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/crypto@v0.10.0
0.56.0

Open the chart page →

2,908

Container images carrying it

3,391 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.56.0
1
ethpandaops/execution-processor:latest5c4832e9588f
golang.org/x/crypto@v0.43.0
0.56.0
1
ethpandaops/forky:debian-latestc937f4ba737c
golang.org/x/crypto@v0.49.0
0.56.0
1
ethpandaops/panda-pulse:latestad6fc3b3e6b8
golang.org/x/crypto@v0.51.0
0.56.0
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
golang.org/x/crypto@v0.41.0
0.56.0
1
ethpandaops/service-authenticatoor:main27b8e5ea3125
golang.org/x/crypto@v0.37.0
0.56.0
1
ethpandaops/spamoor:latest5f731b20ec50
golang.org/x/crypto@v0.52.0
0.56.0
1
ethpandaops/splitoor:latest989da6bea4bd
golang.org/x/crypto@v0.36.0
0.56.0
1
evcc/evcc:0.315.0327318279998
golang.org/x/crypto@v0.55.0
0.56.0
1
evcc/evcc:0.300.8ddf2a25afce5
golang.org/x/crypto@v0.47.0
0.56.0
1
everpcpc/channels:latestb378d137ae8b
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.56.0
1
factly/dega-api:0.15.166fafc7b0a17
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0
1
factly/dega-server:0.15.194d21479382e
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0
1
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0
1
factly/mande-server:0.34.1384d384310ef
golang.org/x/crypto@v0.1.0
0.56.0
1
factly/vidcheck-server:0.12.087064eb0463c
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0
1
falcosecurity/event-generator:latest932956d86c99
golang.org/x/crypto@v0.51.0
0.56.0
1
falcosecurity/falco:0.44.1d0cfe422d6ac
golang.org/x/crypto@v0.47.0
0.56.0
1
falcosecurity/falcoctl:0.13.00eeb79adc580
golang.org/x/crypto@v0.50.0
0.56.0
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
golang.org/x/crypto@v0.50.0
0.56.0
1
falcosecurity/falcosidekick:2.32.01976da721518
golang.org/x/crypto@v0.41.0
0.56.0
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.56.0
1
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
golang.org/x/crypto@v0.22.0
0.56.0
1
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.56.0
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.56.0
1
filebrowser/filebrowser:v2.63.15-s6dbac07403040
golang.org/x/crypto@v0.53.0
0.56.0
1
fission/fission-bundle:1.14.13fcfd8a0fa5d
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.56.0
1
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.56.0
1
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/crypto@v0.9.0
0.56.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
golang.org/x/crypto@v0.37.0
0.56.0
1
flashbots/mev-boost:1.8.07c486b5789da
golang.org/x/crypto@v0.23.0
0.56.0
1
flashcatcloud/categraf:latest42e6ab16472e
golang.org/x/crypto@v0.52.0
0.56.0
1
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/crypto@v0.45.0
0.56.0
1
fleetdm/fleet:v4.66.012e644b7f40e
golang.org/x/crypto@v0.35.0
0.56.0
1
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/crypto@v0.9.0
0.56.0
1
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/crypto@v0.9.0
0.56.0
1
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
golang.org/x/crypto@v0.5.0
0.56.0
1
flomesh/osm-edge-controller:1.3.9add7a4da4622
golang.org/x/crypto@v0.5.0
0.56.0
1
flomesh/osm-edge-injector:1.3.947287e3ad324
golang.org/x/crypto@v0.5.0
0.56.0
1
fluxcd/flux-cli:v2.9.5704d55295355
golang.org/x/crypto@v0.53.0
0.56.0
1
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.56.0
1
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.56.0
1
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/crypto@v0.17.0
0.56.0
1
foomo/contentserver:1.21.0824f41463e9b
golang.org/x/crypto@v0.54.0
0.56.0
1
fosrl/newt:1.10.4ccd2b0e9a049
golang.org/x/crypto@v0.48.0
0.56.0
1
foxcpp/maddy:0.7.16ab538e2f28b
golang.org/x/crypto@v0.18.0
0.56.0
1
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.56.0
1
foxcpp/maddy:0.9.2a4b839985b9b
golang.org/x/crypto@v0.32.0
0.56.0
1
foxcpp/maddy:0.8.2eeb5813fc4d1
golang.org/x/crypto@v0.32.0
0.56.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.56.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.