StackRadar

CVE-2026-56855

Unscored

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,116
of 17,821 indexed, latest versions
Container images
3,454
deployed by those charts
Fix available
1 of 1
affected package

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Carried by container images the latest versions of 3,116 of 17,821 indexed charts deploy, on 3,454 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+158 more0.56.03,454
OSV records
GO-2026-6355

Charts affected

3,116 by stars
ChartLatestAffected imagesRadar Score
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
wernight/ngrok:latestd211f29ebcfe
golang.org/x/crypto@v0.17.0
0.56.0

Open the chart page →

3,020
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.56.0

Open the chart page →

24,397
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.56.0

Open the chart page →

25,575
podgrabnicholaswildeVerified publisher0.1.01 of 1See more

podgrab nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.56.0

Open the chart page →

2,402
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.56.0

Open the chart page →

22,448
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.56.0

Open the chart page →

23,651
twtxtnicholaswildeVerified publisher1.0.01 of 1See more

twtxt nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
golang.org/x/crypto@v0.0.0-20200709230013-948cd5f35899
0.56.0

Open the chart page →

2,334
cert-managernicklasfrahm-cert-managerVerified publisher0.1.24 of 4See more

cert-manager nicklasfrahm-cert-manager 0.1.2

4 of the 4 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.18.2af59e01ad975
golang.org/x/crypto@v0.38.0
0.56.0
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
golang.org/x/crypto@v0.38.0
0.56.0
quay.io/jetstack/cert-manager-startupapicheck:v1.18.21075e0974151
golang.org/x/crypto@v0.38.0
0.56.0
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
golang.org/x/crypto@v0.38.0
0.56.0

Open the chart page →

2,856
ciliumnicklasfrahm-ciliumVerified publisher0.7.42 of 6See more

cilium nicklasfrahm-cilium 0.7.4

2 of the 6 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
golang.org/x/crypto@v0.40.0
0.56.0
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
golang.org/x/crypto@v0.40.0
0.56.0

Open the chart page →

7,266
metrics-servernicklasfrahm-metrics-serverVerified publisher0.1.11 of 1See more

metrics-server nicklasfrahm-metrics-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/crypto@v0.38.0
0.56.0

Open the chart page →

799
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
golang.org/x/crypto@v0.43.0
0.56.0

Open the chart page →

2,520
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
golang.org/x/crypto@v0.28.0
0.56.0

Open the chart page →

1,842
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
golang.org/x/crypto@v0.14.0
0.56.0

Open the chart page →

1,188
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
golang.org/x/crypto@v0.11.0
0.56.0

Open the chart page →

3,427
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
golang.org/x/crypto@v0.14.0
0.56.0

Open the chart page →

1,120
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/crypto@v0.9.0
0.56.0

Open the chart page →

1,440
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/crypto@v0.38.0
0.56.0

Open the chart page →

1,870
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/crypto@v0.38.0
0.56.0

Open the chart page →

1,870
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/crypto@v0.40.0
0.56.0

Open the chart page →

6,628
firehose-ethereumnodeifyVerified publisher1.7.11 of 2See more

firehose-ethereum nodeify 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/crypto@v0.37.0
0.56.0

Open the chart page →

5,742
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/crypto@v0.0.0-20220817201139-bc19a97f63c8
0.56.0

Open the chart page →

4,785
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/crypto@v0.16.0
0.56.0

Open the chart page →

2,986
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/crypto@v0.11.0
0.56.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/crypto@v0.8.0
0.56.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/crypto@v0.8.0
0.56.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/crypto@v0.11.0
0.56.0
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/crypto@v0.8.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/crypto@v0.9.0
0.56.0

Open the chart page →

7,760
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.56.0

Open the chart page →

4,559
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
golang.org/x/crypto@v0.6.0
0.56.0

Open the chart page →

2,257
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.56.0

Open the chart page →

7,540
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.56.0

Open the chart page →

4,862
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.56.0

Open the chart page →

2,807
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.56.0

Open the chart page →

27,585
nai-knative-servingnutanix-helm-releasesVerified publisher1.13.11 of 4See more

nai-knative-serving nutanix-helm-releases 1.13.1

1 of the 4 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
golang.org/x/crypto@v0.18.0
0.56.0

Open the chart page →

3,766
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.02 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

2 of the 7 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
golang.org/x/crypto@v0.37.0
0.56.0
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.56.0

Open the chart page →

4,999
gpu-operatornvidia-gpu-operator26.7.01 of 2See more

gpu-operator nvidia-gpu-operator 26.7.0

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
golang.org/x/crypto@v0.53.0
0.56.0

Open the chart page →

245
dnscrypt-proxyobeoneVerified publisher1.4.51 of 1See more

dnscrypt-proxy obeone 1.4.5

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
klutchell/dnscrypt-proxy:2.1.18a98e8d13314f
golang.org/x/crypto@v0.54.0
0.56.0

Open the chart page →

71
lensoci-ai-incubations0.1.147 of 16See more

lens oci-ai-incubations 0.1.14

7 of the 16 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/crypto@v0.38.0
0.56.0
grafana/grafana:12.1.1a1701c218024
golang.org/x/crypto@v0.39.0
0.56.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/crypto@v0.14.0
0.56.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/crypto@v0.14.0
0.56.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.85.0ebb560bcb6bd
golang.org/x/crypto@v0.41.0
0.56.0
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
golang.org/x/crypto@v0.39.0
0.56.0
quay.io/prometheus/pushgateway:v1.11.103738d278e08
golang.org/x/crypto@v0.35.0
0.56.0

Open the chart page →

17,198
oci-prometheus-sd-proxyoci-prometheus-sd-proxy1.0.01 of 1See more

oci-prometheus-sd-proxy oci-prometheus-sd-proxy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/amaanx86/oci-prometheus-sd-proxy:latest297a8379a328
golang.org/x/crypto@v0.45.0
0.56.0

Open the chart page →

285
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/crypto@v0.47.0
0.56.0

Open the chart page →

2,358
argocd-agent-addonocm-helm-chartsVerified publisher0.29.02 of 2See more

argocd-agent-addon ocm-helm-charts 0.29.0

2 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
golang.org/x/crypto@v0.47.0
0.56.0
quay.io/open-cluster-management/argocd-pull-integration:0.29.006b4b9b3c3ed
golang.org/x/crypto@v0.55.0
0.56.0

Open the chart page →

671
argocd-pull-integrationocm-helm-chartsVerified publisher0.29.01 of 1See more

argocd-pull-integration ocm-helm-charts 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/argocd-pull-integration:0.29.006b4b9b3c3ed
golang.org/x/crypto@v0.55.0
0.56.0

Open the chart page →

65
cluster-managerocm-helm-chartsVerified publisher1.3.11 of 1See more

cluster-manager ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/crypto@v0.49.0
0.56.0

Open the chart page →

822
cluster-proxyocm-helm-chartsVerified publisher0.12.01 of 1See more

cluster-proxy ocm-helm-charts 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/crypto@v0.53.0
0.56.0

Open the chart page →

1,352
dynamic-scoring-frameworkocm-helm-chartsVerified publisher0.1.01 of 2See more

dynamic-scoring-framework ocm-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
golang.org/x/crypto@v0.45.0
0.56.0

Open the chart page →

996
klusterletocm-helm-chartsVerified publisher1.3.11 of 1See more

klusterlet ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/crypto@v0.49.0
0.56.0

Open the chart page →

822
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
golang.org/x/crypto@v0.37.0
0.56.0

Open the chart page →

1,619
managed-serviceaccountocm-helm-chartsVerified publisher0.11.01 of 1See more

managed-serviceaccount ocm-helm-charts 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/managed-serviceaccount:v0.11.0aabd4b4dbef8
golang.org/x/crypto@v0.54.0
0.56.0

Open the chart page →

44
multicluster-controlplaneocm-helm-chartsVerified publisher0.8.01 of 1See more

multicluster-controlplane ocm-helm-charts 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
golang.org/x/crypto@v0.49.0
0.56.0

Open the chart page →

626
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.56.0

Open the chart page →

2,132
octantoctant0.1.861 of 1See more

octant octant 0.1.86

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/mydecisive/octant:0.1.86ebbd44abae6c
golang.org/x/crypto@v0.49.0
0.56.0

Open the chart page →

566
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
golang.org/x/crypto@v0.6.0
0.56.0

Open the chart page →

5,853
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.56.0

Open the chart page →

8,550
mailpitoli-the-devVerified publisher1.0.11 of 1See more

mailpit oli-the-dev 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56855.

Container imageDigestPackageFixed in
axllent/mailpit:v1.31.0c96991d9bef7
golang.org/x/crypto@v0.55.0
0.56.0

Open the chart page →

165

Container images carrying it

3,454 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/crypto@v0.37.0
0.56.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/crypto@v0.36.0
0.56.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
golang.org/x/crypto@v0.53.0
0.56.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.56.0
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.