StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,607
of 17,832 indexed, latest versions
Container images
5,310
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,607 of 17,832 indexed charts deploy, on 5,310 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,310
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,607 by stars
ChartLatestAffected imagesRadar Score
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
stdlib@go1.17.5
1.25.13

Open the chart page →

6,630
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
stdlib@go1.22.11
1.25.13

Open the chart page →

7,070
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.13

Open the chart page →

1,263
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
stdlib@go1.25.8
1.25.13

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.13
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.13

Open the chart page →

4,362
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.13

Open the chart page →

14,673
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
stdlib@go1.18.4
1.25.13

Open the chart page →

1,986
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
stdlib@go1.16.1
1.25.13
prom/prometheus:v2.22.2f7ffebdd428b
stdlib@go1.15.5
1.25.13
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
stdlib@go1.16.5
1.25.13
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
stdlib@go1.16.5
1.25.13

Open the chart page →

16,546
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
stdlib@go1.21.7
1.25.13

Open the chart page →

1,961
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
stdlib@go1.18.10
1.25.13

Open the chart page →

1,584
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
stdlib@go1.16.3
1.25.13

Open the chart page →

6,601
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.13
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
stdlib@go1.13.11
1.25.13
squareup/ghostunnel:v1.5.270f4cf270425
stdlib@go1.13.4
1.25.13
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
stdlib@go1.14.3
1.25.13

Open the chart page →

12,257
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
stdlib@go1.19.10
1.25.13

Open the chart page →

1,316
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
stdlib@go1.17.8
1.25.13

Open the chart page →

1,828
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
stdlib@go1.13.5
1.25.13

Open the chart page →

4,225
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.25.13

Open the chart page →

13,694
steadybit-agentsteadybit3.1.1701See more

steadybit-agent steadybit 3.1.170

1 container image this version deploys carries CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/steadybit/extension-host:v1.8.103a5ef26aac5
stdlib@go1.25.12
1.25.13

Open the chart page →

pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
snapshot-controllerstevehipwellVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.13

Open the chart page →

495
vertical-pod-autoscalerstevehipwellVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
stdlib@go1.26.5
1.25.13

Open the chart page →

228
snapshot-controllerstevehipwell-helm-charts-snapshot-controllerVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell-helm-charts-snapshot-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.13

Open the chart page →

495
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.13

Open the chart page →

1,530
meerkat-crmstone0.3.01 of 1See more

meerkat-crm stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/fbuchner/meerkat-crm:1.7.0d513bdd3ae80
stdlib@go1.26.5
1.25.13

Open the chart page →

104
pulsar-resources-operatorstreamnative0.21.21 of 1See more

pulsar-resources-operator streamnative 0.21.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
streamnative/pulsar-resources-operator:v0.21.282434bb2a8ad
stdlib@go1.25.12
1.25.13

Open the chart page →

128
sn-platform-slimstreamnative1.11.453 of 6See more

sn-platform-slim streamnative 1.11.45

3 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.13
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
stdlib@go1.20.4
1.25.13
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.13

Open the chart page →

64,468
supabase-operatorstrrl-helm2026.7.251 of 1See more

supabase-operator strrl-helm 2026.7.25

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/strrl/supabase-operator:2026.7.2587d083ab8980
stdlib@go1.25.12
1.25.13

Open the chart page →

237
wonder-mesh-netstrrl-helm2026.629.02 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
headscale/headscale:0.27.1cd37b3001857
stdlib@go1.25.1
1.25.13
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
stdlib@go1.25.11
1.25.13

Open the chart page →

5,188
stunner-devstunner1.2.12 of 2See more

stunner-dev stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-gateway-operator-devstunner1.1.12 of 2See more

stunner-gateway-operator-dev stunner 1.1.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-premiumstunner1.2.12 of 2See more

stunner-premium stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
stdlib@go1.26.4
1.25.13
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13

Open the chart page →

269
stunner-prometheusstunner0.2.14 of 4See more

stunner-prometheus stunner 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.26.5
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
stdlib@go1.23.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
stdlib@go1.23.2
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.13

Open the chart page →

3,067
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
stdlib@go1.24.3
1.25.13

Open the chart page →

2,650
orchestratorsubstraVerified publisher8.8.02 of 3See more

orchestrator substra 8.8.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
stdlib@go1.24.6
1.25.13
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
stdlib@go1.21.13
1.25.13

Open the chart page →

2,641
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
stdlib@go1.24.6
1.25.13

Open the chart page →

4,895
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
stdlib@go1.22.5
1.25.13

Open the chart page →

1,597
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
stdlib@go1.15.2
1.25.13

Open the chart page →

2,355
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
stdlib@go1.17.8
1.25.13

Open the chart page →

2,072
stresssudermanjr0.2.01 of 1See more

stress sudermanjr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
stdlib@go1.26.5
1.25.13

Open the chart page →

791
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.13

Open the chart page →

2,132
ingress-nginx-external-lbsuminhong1.0.02 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
stdlib@go1.22.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
stdlib@go1.21.6
1.25.13

Open the chart page →

2,095
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
stdlib@go1.20.7
1.25.13

Open the chart page →

1,807
hello-worldsumudu-repo1.0.01 of 1See more

hello-world sumudu-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
sumuduliya/hello-world:latestb7788a2984a3
stdlib@go1.19.13
1.25.13

Open the chart page →

941
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
supabase-operatorsupabse0.1.31 of 1See more

supabase-operator supabse 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/supabase-community/supabase-operator:v0.1.3253a6dcbf4f0
stdlib@go1.25.12
1.25.13

Open the chart page →

237
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
stdlib@go1.17.6
1.25.13

Open the chart page →

2,372
superset-operatorsuperset-kubernetes-operatorVerified publisher0.2.01 of 1See more

superset-operator superset-kubernetes-operator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/apache/superset-kubernetes-operator:0.2.04351831f757f
stdlib@go1.26.5
1.25.13

Open the chart page →

111
do-database-metrics-adaptersupporttools1.0.21 of 1See more

do-database-metrics-adapter supporttools 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
supporttools/do-database-metrics-adapter:1.0.2ab55fd5a69c3
stdlib@go1.22.3
1.25.13

Open the chart page →

430
do-operatorsupporttools0.1.71 of 2See more

do-operator supporttools 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
digitalocean/do-operator:v0.1.65e5deb4db76e
stdlib@go1.18.10
1.25.13

Open the chart page →

1,063
go-redis-proxysupporttools0.0.71 of 1See more

go-redis-proxy supporttools 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
supporttools/go-redis-proxy:0.0.7cbd45f6b02b8
stdlib@go1.21.6
1.25.13

Open the chart page →

529
go-web-cachesupporttools1.3.21 of 1See more

go-web-cache supporttools 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
supporttools/go-web-cache:v1.3.2f4f775dd43b9
stdlib@go1.21.6
1.25.13

Open the chart page →

512

Container images carrying it

5,310 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/zncdatadev/commons-operator:0.4.01a353def9fe1
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/dolphinscheduler-operator:0.4.0d0a4e55eeb7f
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/hbase-operator:0.4.069e9a1b0daf8
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/hdfs-operator:0.4.0eb3c2928250e
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/hive-operator:0.4.0d66ba9149c22
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/kafka-operator:0.4.00a0b4c39c1ba
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/listener-csi-driver:0.4.0b69bed123b02
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/listener-operator:0.4.068b92dae8d75
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/nifi-operator:0.4.0bb4e26ff5e2f
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/secret-csi-driver:0.4.0604a7d98ab58
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/spark-k8s-operator:0.4.0d3f2b10c4a6d
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/superset-operator:0.4.0102e66e32218
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/trino-operator:0.4.04f516757aee3
stdlib@go1.25.8
1.25.13
1
quay.io/zncdatadev/zookeeper-operator:0.4.0b4f33d89ac45
stdlib@go1.25.8
1.25.13
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
stdlib@go1.19.1
1.25.13
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.25.13
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
stdlib@go1.18.1
1.25.13
1
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.25.13
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.25.13
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
stdlib@go1.19.10
1.25.13
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
stdlib@go1.20.8
1.25.13
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
stdlib@go1.19.13
1.25.13
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.25.13
1
registry.gitlab.com/dyff/dyff-operator:0.24.20e9ca51627601
stdlib@go1.24.13
1.25.13
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
stdlib@go1.26.5
1.25.13
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
stdlib@go1.20.14
1.25.13
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
stdlib@go1.25.7
1.25.13
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
stdlib@go1.25.7
1.25.13
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.25.13
1
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.07757679afa1b
stdlib@go1.22.0
1.25.13
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
stdlib@go1.26.4
1.25.13
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.13
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.25.13
1
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.25448611a3c54
stdlib@go1.26.5
1.25.13
1
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.13
1
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.13
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.13
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.25.13
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.13
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.13
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
stdlib@go1.24.9
1.25.13
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
stdlib@go1.26.5
1.25.13
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
stdlib@go1.24.5
1.25.13
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.13
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.93.006a950310ecd
stdlib@go1.26.2
1.25.13
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
stdlib@go1.26.4
1.25.13
1
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
stdlib@go1.26.5
1.25.13
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.13
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
stdlib@go1.24.4
1.25.13
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
stdlib@go1.24.7
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.