StackRadar

CVE-2026-56858

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,638
of 17,828 indexed, latest versions
Container images
5,364
deployed by those charts
Fix available
1 of 2
affected packages

Fix Javascript regexp context tracking in html/template

Carried by container images the latest versions of 4,638 of 17,828 indexed charts deploy, on 5,364 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,364
OSV records
DEBIAN-CVE-2026-56858GO-2026-6091
Also known as
BIT-golang-2026-56858

Charts affected

4,638 by stars
ChartLatestAffected imagesRadar Score
vm-standaloneot-container-kit0.0.44 of 6See more

vm-standalone ot-container-kit 0.0.4

4 of the 6 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
stdlib@go1.26.2
1.25.13
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
stdlib@go1.25.9
1.25.13
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
stdlib@go1.26.2
1.25.13
quay.io/opstree/victoriametrics-operator:v0.69.066fe5216c278
stdlib@go1.26.2
1.25.13

Open the chart page →

3,501
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
stdlib@go1.24.3
1.25.13

Open the chart page →

734
otsotsVerified publisher1.8.41 of 2See more

ots ots 1.8.4

1 of the 2 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/luzifer/ots:v1.21.5c94f6c9ed173
stdlib@go1.26.2
1.25.13

Open the chart page →

367
akash-hostname-operatorovrclk-211.5.11 of 1See more

akash-hostname-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
stdlib@go1.23.5
1.25.13

Open the chart page →

3,561
akash-inventory-operatorovrclk-211.5.11 of 1See more

akash-inventory-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
stdlib@go1.23.5
1.25.13

Open the chart page →

3,561
akash-ip-operatorovrclk-211.5.11 of 1See more

akash-ip-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
stdlib@go1.23.5
1.25.13

Open the chart page →

3,561
akash-nodeovrclk-211.1.31 of 1See more

akash-node ovrclk-2 11.1.3

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/akash-network/node:0.36.08763983b31f1
stdlib@go1.21.10
1.25.13

Open the chart page →

1,338
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
stdlib@go1.24.3
1.25.13

Open the chart page →

1,033
httpbunowan-charts0.1.01 of 1See more

httpbun owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
sharat87/httpbun:latest405332d9050a
stdlib@go1.25.1
1.25.13

Open the chart page →

314
minioowan-charts0.1.22 of 2See more

minio owan-charts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
cleanstart/minio:latest544bdb8811e1
stdlib@go1.26.4
1.25.13
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
stdlib@go1.24.4
1.25.13

Open the chart page →

1,083
shlinkowan-charts0.1.01 of 1See more

shlink owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
shlinkio/shlink:stable666cc24edf72
stdlib@go1.26.4
1.25.13

Open the chart page →

322
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
stdlib@go1.17
1.25.13

Open the chart page →

1,826
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
stdlib@go1.22.5
1.25.13

Open the chart page →

1,998
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
stdlib@go1.22.1
1.25.13

Open the chart page →

3,726
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
stdlib@go1.22.5
1.25.13

Open the chart page →

3,353
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
stdlib@go1.21.1
1.25.13
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
stdlib@go1.21.1
1.25.13

Open the chart page →

2,338
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
stdlib@go1.23.5
1.25.13

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.13
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.13
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.13

Open the chart page →

28,008
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:80744ee5ef89c
stdlib@go1.24.6
1.25.13

Open the chart page →

19,773
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
stdlib@go1.24.0
1.25.13

Open the chart page →

3,649
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-draco1.0.01 of 3See more

pages pages-draco 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-ellora1.0.01 of 3See more

pages pages-ellora 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-finchley1.0.01 of 3See more

pages pages-finchley 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-fornax1.0.01 of 3See more

pages pages-fornax 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-harsh1.0.01 of 3See more

pages pages-harsh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespagesk1.0.01 of 3See more

pages pagesk 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-microservice-ashim1.0.01 of 3See more

pages pages-microservice-ashim 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-mihai1.0.01 of 3See more

pages pages-mihai 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-nivesh1.0.01 of 3See more

pages pages-nivesh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespagessandeepgudu1.0.01 of 3See more

pages pagessandeepgudu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-shubhanker1.0.01 of 3See more

pages pages-shubhanker 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-ssharma09091.0.01 of 3See more

pages pages-ssharma0909 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-sucharitha1.0.01 of 3See more

pages pages-sucharitha 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56858.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350

Container images carrying it

5,364 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
stdlib@go1.24.4
1.25.13
1
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
stdlib@go1.26.2
1.25.13
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.25.13
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
stdlib@go1.21.12
1.25.13
1
ghcr.io/movetokube/postgres-operator:2.4.0def57d85a2da
stdlib@go1.25.5
1.25.13
1
ghcr.io/mrueg/netcupscp-exporter:v0.5.25b86c2c0b0e0
stdlib@go1.26.5
1.25.13
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
stdlib@go1.19.8
1.25.13
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
stdlib@go1.23.6
1.25.13
1
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.25.13
1
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
stdlib@go1.23.12
1.25.13
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
stdlib@go1.25.7
1.25.13
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
stdlib@go1.25.5
1.25.13
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
stdlib@go1.25.7
1.25.13
1
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
stdlib@go1.15.6
1.25.13
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
stdlib@go1.19.5
1.25.13
1
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
stdlib@go1.26.0
1.25.13
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
stdlib@go1.25.6
1.25.13
1
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
stdlib@go1.21.1
1.25.13
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
stdlib@go1.21.11
1.25.13
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.25.13
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
stdlib@go1.22.4
1.25.13
1
ghcr.io/netbirdio/netbird-operator:v0.8.0ae2c26cfc547
stdlib@go1.26.5
1.25.13
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
stdlib@go1.16.6
1.25.13
1
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
stdlib@go1.17
1.25.13
1
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
stdlib@go1.16.8
1.25.13
1
ghcr.io/nginx/nginx-gateway-fabric:2.4.180f3a0a51af5
stdlib@go1.25.7
1.25.13
1
ghcr.io/nginx/nginx-gateway-fabric:2.6.6c10f734589e9
stdlib@go1.26.4
1.25.13
1
ghcr.io/nicholaswilde/golinks:version-154c5818e67b26324c5
stdlib@go1.16.5
1.25.13
1
ghcr.io/nicholaswilde/installer:version-0.2.947d8ecd310a9
stdlib@go1.15.3
1.25.13
1
ghcr.io/nicholaswilde/notes:version-ee287b9ab9bc16465bc
stdlib@go1.16.5
1.25.13
1
ghcr.io/nicholaswilde/olivetin:version-2021-07-19e1d5c8a01008
stdlib@go1.16.5
1.25.13
1
ghcr.io/nicholaswilde/shiori:version-v1.5.0e0645abe6777
stdlib@go1.16.5
1.25.13
1
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.25.13
1
ghcr.io/nicholaswilde/todo:941c0d3-ls1d7ba1341a940
stdlib@go1.14.15
1.25.13
1
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
stdlib@go1.16.5
1.25.13
1
ghcr.io/nicholaswilde/wiki:version-900b76a6c4f261d8f5e
stdlib@go1.16.5
1.25.13
1
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
stdlib@go1.15.12
1.25.13
1
ghcr.io/niklas-letz/cert-manager-webhook-solidserver:1.0.2f19a306ce759
stdlib@go1.26.4
1.25.13
1
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
stdlib@go1.17.6
1.25.13
1
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
stdlib@go1.24.13
1.25.13
1
ghcr.io/nlamirault/bbox_exporter:1.0.0f5dd1f7794c6
stdlib@go1.18.3
1.25.13
1
ghcr.io/nlamirault/freebox-exporter:1.0.02d522b664e12
stdlib@go1.19.2
1.25.13
1
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
stdlib@go1.24.5
1.25.13
1
ghcr.io/nnstd/seaweedfs-operator:1.43ebe2fd253f6
stdlib@go1.24.5
1.25.13
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
stdlib@go1.19.4
1.25.13
1
ghcr.io/nousefreak/clusterfan:v0.1.04ea05e2a7b57
stdlib@go1.17.5
1.25.13
1
ghcr.io/nowakeai/kube-insight:v0.1.475849fe6548a
stdlib@go1.26.4
1.25.13
1
ghcr.io/o0th/cert-manager-webhook-bunny:1.0.2fe7ce555a12d
stdlib@go1.23.5
1.25.13
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
stdlib@go1.24.6
1.25.13
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
stdlib@go1.24.7
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.