StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,700
of 17,985 indexed, latest versions
Container images
5,367
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,700 of 17,985 indexed charts deploy, on 5,367 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,367
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,700 by stars
ChartLatestAffected imagesRadar Score
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.13

Open the chart page →

14,908
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.13

Open the chart page →

14,141
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.13

Open the chart page →

5,492
flyte-binaryflyte2.0.501 of 4See more

flyte-binary flyte 2.0.50

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.25.13

Open the chart page →

4,627
flyte-coreflyte2.0.501 of 3See more

flyte-core flyte 2.0.50

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.25.13

Open the chart page →

480
frp-operatorfrpVerified publisher1.0.41 of 1See more

frp-operator frp 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/aureum-cloud/frp-operator:v1.0.196b01d7e7025
stdlib@go1.24.13
1.25.13

Open the chart page →

388
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
stdlib@go1.23.12
1.25.13

Open the chart page →

559
ascii-moviegabe565Verified publisher0.16.41 of 1See more

ascii-movie gabe565 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.25.13

Open the chart page →

1,238
domain-watchgabe565Verified publisher1.1.01 of 1See more

domain-watch gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
stdlib@go1.24.1
1.25.13

Open the chart page →

1,051
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
stdlib@go1.17.7
1.25.13

Open the chart page →

3,043
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.25.13

Open the chart page →

1,114
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
stdlib@go1.15.10
1.25.13

Open the chart page →

1,755
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
stdlib@go1.17.10
1.25.13

Open the chart page →

7,906
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.25.13
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
stdlib@go1.13.10
1.25.13

Open the chart page →

4,774
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.25.13

Open the chart page →

10,068
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
stdlib@go1.17.8
1.25.13

Open the chart page →

10,626
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.25.13

Open the chart page →

2,348
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
stdlib@go1.14.13
1.25.13

Open the chart page →

3,382
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
stdlib@go1.17
1.25.13

Open the chart page →

2,609
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.25.13

Open the chart page →

11,179
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.25.13

Open the chart page →

2,230
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.25.13

Open the chart page →

12,436
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.22 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.485b9bf2e29cf
stdlib@go1.24.6
1.25.13
ghcr.io/sredevopsorg/ghost-on-kubernetes:main06adb21bfdfc
stdlib@go1.26.4
1.25.13

Open the chart page →

1,979
gitlab-runnergitlab-jh0.93.01 of 1See more

gitlab-runner gitlab-jh 0.93.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
stdlib@go1.26.5
1.25.13

Open the chart page →

309
gitvotegitvoteVerified publisher1.5.02 of 6See more

gitvote gitvote 1.5.0

2 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.25.13
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
stdlib@go1.25.3
1.25.13

Open the chart page →

6,014
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.25.13

Open the chart page →

2,298
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.25.13

Open the chart page →

6,759
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
stdlib@go1.13.7
1.25.13

Open the chart page →

1,660
whoamiharrytangVerified publisher0.2.01 of 1See more

whoami harrytang 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.13

Open the chart page →

356
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
stdlib@go1.23.1
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.25.13

Open the chart page →

2,168
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
stdlib@go1.23.1
1.25.13

Open the chart page →

571
headscaleheadscaleVerified publisher1.0.203 of 3See more

headscale headscale 1.0.20

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/k8s:1.37.0b421c2e9419e
stdlib@go1.26.5
1.25.13
ghcr.io/juanfont/headscale:0.29.4-debug2380cdb4951e
stdlib@go1.26.5
1.25.13
ghcr.io/juanfont/headscale:0.29.48833f828b414
stdlib@go1.26.5
1.25.13

Open the chart page →

1,746
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
stdlib@go1.17.2
1.25.13

Open the chart page →

1,564
netbirdhelmforgeVerified publisher1.0.111 of 4See more

netbird helmforge 1.0.11

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.25.13

Open the chart page →

2,763
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.21 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
stdlib@go1.25.7
1.25.13

Open the chart page →

2,586
helm-watchdog-pod-deletehelm-watchdog-pod-delete0.3.01 of 1See more

helm-watchdog-pod-delete helm-watchdog-pod-delete 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.25.13

Open the chart page →

1,198
hermes-agenthermes-agentVerified publisher1.16.01 of 1See more

hermes-agent hermes-agent 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.25.13

Open the chart page →

6,273
home-assistanthome-assistantVerified publisher0.5.111 of 3See more

home-assistant home-assistant 0.5.11

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.3d89226851697
stdlib@go1.25.6
1.25.13

Open the chart page →

2,866
hpe-cosi-driverhpe-storageVerified publisher2.0.02 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
stdlib@go1.25.0
1.25.13
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.13

Open the chart page →

1,777
inference-manager-engineinference-manager-engine1.46.01 of 1See more

inference-manager-engine inference-manager-engine 1.46.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
stdlib@go1.25.9
1.25.13

Open the chart page →

276
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
stdlib@go1.19.5
1.25.13

Open the chart page →

2,622
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.21.11 of 5See more

infrahub-enterprise infrahub-enterprise 4.21.1

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13

Open the chart page →

12,095
inlets-operatorinlets0.17.201 of 1See more

inlets-operator inlets 0.17.20

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/inlets/inlets-operator:0.17.2208265c006973
stdlib@go1.26.2
1.25.13

Open the chart page →

502
coreinstill-aiOfficialVerified publisher0.1.7511 of 15See more

core instill-ai 0.1.75

11 of the 15 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.25.13
instill/api-gateway:9bfdc88b53eaa51c523
stdlib@go1.25.6
1.25.13
instill/artifact-backend:b28766ac4a393e601ed
stdlib@go1.25.6
1.25.13
instill/console:0.68.54cd70e2df5c6
stdlib@go1.23.10
1.25.13
instill/mgmt-backend:d0933d4ebe12f77a3f9
stdlib@go1.25.6
1.25.13
instill/model-backend:611f0f2e980125e5ba5
stdlib@go1.25.6
1.25.13
library/influxdb:2.3.0-alpined7f5dd5f70e2
stdlib@go1.18.3
1.25.13
library/postgres:15-alpinea46e076249ce
stdlib@go1.24.6
1.25.13
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.25.13
openfga/openfga:v1.9.25e94966c11df
stdlib@go1.24.5
1.25.13
temporalio/admin-tools:1.28cfde8170c92f
stdlib@go1.25.8
1.25.13

Open the chart page →

32,958
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
stdlib@go1.23.4
1.25.13

Open the chart page →

576
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
stdlib@go1.15.6
1.25.13

Open the chart page →

2,207
amazon-eks-pod-identity-webhookjkroepkeVerified publisher2.6.51 of 1See more

amazon-eks-pod-identity-webhook jkroepke 2.6.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/eks/amazon-eks-pod-identity-webhook:v0.6.173071570e8e8c
stdlib@go1.26.3
1.25.13

Open the chart page →

156
k8s-ephemeral-storage-metricsk8s-ephemeral-storage-metrics1.21.31 of 1See more

k8s-ephemeral-storage-metrics k8s-ephemeral-storage-metrics 1.21.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/k8s-ephemeral-storage-metrics:1.21.38297aa4a9278
stdlib@go1.26.5
1.25.13

Open the chart page →

56
rustrial-k8s-gitops-secrets-controllerk8s-gitops-secrets0.6.01 of 1See more

rustrial-k8s-gitops-secrets-controller k8s-gitops-secrets 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rustrial/k8s-gitops-secrets-controller:0.6.093326a322a01
stdlib@go1.26.4
1.25.13

Open the chart page →

75
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.25.13

Open the chart page →

5,308

Container images carrying it

5,367 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.