StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,652
of 17,832 indexed, latest versions
Container images
5,361
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,652 of 17,832 indexed charts deploy, on 5,361 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,361
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,652 by stars
ChartLatestAffected imagesRadar Score
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
stdlib@go1.18.10
1.25.13

Open the chart page →

925
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.66.0d98e6db8094f
stdlib@go1.23.2
1.25.13

Open the chart page →

2,700
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.13

Open the chart page →

7,739
interlinkinterlink0.6.11 of 2See more

interlink interlink 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/interlink-hq/interlink/virtual-kubelet-inttw:latest0e05a7b49c33
stdlib@go1.24.5
1.25.13

Open the chart page →

2,524
irsa-managerirsa-managerVerified publisher0.3.21 of 1See more

irsa-manager irsa-manager 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/kkb0318/irsa-manager:0.3.296d600ae97b4
stdlib@go1.22.7
1.25.13

Open the chart page →

821
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
stdlib@go1.16.6
1.25.13

Open the chart page →

72,008
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.25.13

Open the chart page →

72,082
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.13

Open the chart page →

72,028
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.13

Open the chart page →

72,028
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
stdlib@go1.16.6
1.25.13

Open the chart page →

72,309
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.25.13

Open the chart page →

1,820
kubernetes-event-exporteritakurahVerified publisher0.2.31 of 1See more

kubernetes-event-exporter itakurah 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/itakurah/kubernetes-event-exporter:v1.78abb52b66557
stdlib@go1.20.14
1.25.13

Open the chart page →

1,142
statpingitscontainedVerified publisher0.1.91 of 1See more

statping itscontained 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
statping/statping:v0.90.6532f26fffca46
stdlib@go1.14.8
1.25.13

Open the chart page →

3,539
traefik-forward-authitscontainedVerified publisher1.0.21 of 1See more

traefik-forward-auth itscontained 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.25.13

Open the chart page →

2,235
jenkinsjenkins-cicd-tool0.1.01 of 1See more

jenkins jenkins-cicd-tool 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.13

Open the chart page →

2,582
jessejesse-chartVerified publisher0.0.462 of 6See more

jesse jesse-chart 0.0.46

2 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/git:latest6f3b5029566d
stdlib@go1.26.3
1.25.13
library/postgres:alpined3e1620b530c
stdlib@go1.24.6
1.25.13

Open the chart page →

3,622
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
stdlib@go1.17.13
1.25.13

Open the chart page →

9,447
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
stdlib@go1.21.8
1.25.13

Open the chart page →

7,487
forecastlejmmaloney41.1.1201 of 1See more

forecastle jmmaloney4 1.1.120

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
stakater/forecastle:v1.0.13886b24cdef409
stdlib@go1.22.1
1.25.13

Open the chart page →

1,814
rclonejmmaloney42.3.211 of 1See more

rclone jmmaloney4 2.3.21

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rclone/rclone:1.66.0a693c46a6b8b
stdlib@go1.22.1
1.25.13

Open the chart page →

1,763
job-manager-dispatcherjob-manager-dispatcher1.27.01 of 1See more

job-manager-dispatcher job-manager-dispatcher 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
stdlib@go1.23.12
1.25.13

Open the chart page →

479
job-manager-serverjob-manager-server1.27.01 of 1See more

job-manager-server job-manager-server 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
stdlib@go1.23.12
1.25.13

Open the chart page →

757
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
stdlib@go1.20.5
1.25.13

Open the chart page →

1,079
joylive-injectorjoyliveOfficialVerified publisher1.3.51 of 2See more

joylive-injector joylive 1.3.5

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
otel/opentelemetry-collector:0.100.09e36620d6c2c
stdlib@go1.22.2
1.25.13

Open the chart page →

1,291
ejabberdjuniorjpdj0.1.481 of 1See more

ejabberd juniorjpdj 0.1.48

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/containers/ejabberd-captcha:26.07-r110c57cbc7ad0
stdlib@go1.25.12
1.25.13

Open the chart page →

277
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
stdlib@go1.18.7
1.25.13

Open the chart page →

3,384
k8s-ephemeral-storage-metricsk8s-ephemeral-storage-metrics1.21.31 of 1See more

k8s-ephemeral-storage-metrics k8s-ephemeral-storage-metrics 1.21.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/k8s-ephemeral-storage-metrics:1.21.38297aa4a9278
stdlib@go1.26.5
1.25.13

Open the chart page →

56
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.3213 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

13 of the 17 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/alloy:v1.14.0f50931848bd8
stdlib@go1.25.7
1.25.13
grafana/grafana:12.3.12175aaa91c96
stdlib@go1.25.5
1.25.13
grafana/loki:3.6.73c8fd3570dd9
stdlib@go1.24.13
1.25.13
grafana/loki-canary:3.6.70dac7d5cb383
stdlib@go1.24.13
1.25.13
grafana/tempo:2.9.065a578975943
stdlib@go1.25.1
1.25.13
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
stdlib@go1.23.4
1.25.13
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
stdlib@go1.23.4
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
stdlib@go1.25.6
1.25.13
quay.io/prometheus/alertmanager:v0.31.188b605de9aba
stdlib@go1.25.7
1.25.13
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
stdlib@go1.25.3
1.25.13
quay.io/prometheus/prometheus:v3.10.07571a304e67f
stdlib@go1.26.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.13

Open the chart page →

15,831
karpenterkarpenter-provider-gcpVerified publisher0.6.11 of 1See more

karpenter karpenter-provider-gcp 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudpilotai/gcp/karpenter:v0.6.101946ed4e599
stdlib@go1.26.5
1.25.13

Open the chart page →

119
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
stdlib@go1.24.7
1.25.13

Open the chart page →

8,306
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
stdlib@go1.24.4
1.25.13

Open the chart page →

5,923
mongodb-operatorkeiailabVerified publisher1.16.91 of 1See more

mongodb-operator keiailab 1.16.9

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/keiailab/mongodb-operator:v1.16.9cf6d86e057bb
stdlib@go1.26.5
1.25.13

Open the chart page →

127
valkey-operatorkeiailabVerified publisher1.5.21 of 1See more

valkey-operator keiailab 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/keiailab/valkey-operator:1.5.249b5aef82877
stdlib@go1.26.5
1.25.13

Open the chart page →

127
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.25.13

Open the chart page →

5,314
keycloakkeycloak1.13.71 of 2See more

keycloak keycloak 1.13.7

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.13

Open the chart page →

349
keycloak-client-operatorkeycloak-client-operator0.9.11 of 1See more

keycloak-client-operator keycloak-client-operator 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.13

Open the chart page →

522
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.13

Open the chart page →

5,355
giteakeyporttech0.2.102 of 4See more

gitea keyporttech 0.2.10

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
stdlib@go1.14.8
1.25.13
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.13

Open the chart page →

5,410
kikplatekikplateVerified publisher0.22.02 of 3See more

kikplate kikplate 0.22.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.13
ghcr.io/kikplate/kikplate-api:main2fbce0601a3c
stdlib@go1.25.11
1.25.13

Open the chart page →

2,583
glpikitsune-itopsVerified publisher1.0.71 of 3See more

glpi kitsune-itops 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mariadb:latestd4fdec0510ad
stdlib@go1.24.6
1.25.13

Open the chart page →

3,819
kokukokuVerified publisher1.0.02 of 7See more

koku koku 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
stdlib@go1.23.5
1.25.13
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
stdlib@go1.23.0
1.25.13

Open the chart page →

11,435
komkomVerified publisher0.3.01 of 1See more

kom kom 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/kkb0318/kom:0.3.04e77eff2d906
stdlib@go1.24.4
1.25.13

Open the chart page →

398
kronos-corekronos-coreVerified publisher0.4.11 of 2See more

kronos-core kronos-core 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
kronosorg/kronos-core:v0.4.0301da21c59a5
stdlib@go1.21.10
1.25.13

Open the chart page →

544
kubeadaptkubeadaptVerified publisher1.0.71 of 1See more

kubeadapt kubeadapt 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-agent:v3.0.1d75b6da94913
stdlib@go1.26.2
1.25.13

Open the chart page →

214
kube-arguskube-argusOfficialVerified publisher0.0.1-s2z1 of 1See more

kube-argus kube-argus 0.0.1-s2z

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/manishchaudhary101/kube-argus:latest8e3869d31c70
stdlib@go1.26.5
1.25.13

Open the chart page →

383
cert-managerkubeblocksVerified publisher1.17.24 of 4See more

cert-manager kubeblocks 1.17.2

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
stdlib@go1.23.8
1.25.13
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
stdlib@go1.23.8
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
stdlib@go1.23.8
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
stdlib@go1.23.8
1.25.13

Open the chart page →

2,931
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
stdlib@go1.20.6
1.25.13

Open the chart page →

20,715
ks-corekubeblocksVerified publisher1.1.32 of 5See more

ks-core kubeblocks 1.1.3

2 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
kubesphere/ks-extensions-museum:latest29681958f220
stdlib@go1.20.12
1.25.13
kubesphere/kubectl:v1.27.1649b445b1b732
stdlib@go1.18.10
1.25.13

Open the chart page →

4,741
kubeboltkubeboltVerified publisher2.1.01 of 3See more

kubebolt kubebolt 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.148.0-scratchb269959f3cac
stdlib@go1.26.5
1.25.13

Open the chart page →

397
kubebrowsekubebrowse1.7.02 of 5See more

kubebrowse kubebrowse 1.7.0

2 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/browsersec/kubebrowse:sha-09dfa1fb853e9e6372a
stdlib@go1.24.3
1.25.13
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
stdlib@go1.25.0
1.25.13

Open the chart page →

2,933

Container images carrying it

5,361 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.13
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.13
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.25.13
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.13
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.13
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.13
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.13
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.13
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.13
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.13
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.13
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.