StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,700
of 17,985 indexed, latest versions
Container images
5,367
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,700 of 17,985 indexed charts deploy, on 5,367 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,367
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,700 by stars
ChartLatestAffected imagesRadar Score
lagoon-remotelagoon-chartsVerified publisher0.107.01 of 1See more

lagoon-remote lagoon-charts 0.107.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
stdlib@go1.24.3
1.25.13

Open the chart page →

2,406
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
stdlib@go1.13.10
1.25.13

Open the chart page →

7,568
lgtmlgtmVerified publisher0.28.03 of 9See more

lgtm lgtm 0.28.0

3 of the 9 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
stdlib@go1.26.4
1.25.13
grafana/tempo:2.10.8f0561deb1c68
stdlib@go1.26.5
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.93.1e52bb28fd41c
stdlib@go1.26.5
1.25.13

Open the chart page →

999
lgtm-stacklgtm-stackVerified publisher0.1.35 of 8See more

lgtm-stack lgtm-stack 0.1.3

5 of the 8 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.10f4434c92b3e
stdlib@go1.26.5
1.25.13
grafana/grafana:13.1.0121a7a9ece6d
stdlib@go1.25.7
1.25.13
grafana/loki:3.7.6efd47c67f9ba
stdlib@go1.26.5
1.25.13
grafana/mimir:3.2.0736f7459913d
stdlib@go1.26.5
1.25.13
grafana/tempo:2.10.8f0561deb1c68
stdlib@go1.26.5
1.25.13

Open the chart page →

2,782
keptn-cert-managerlifecycle-toolkitVerified publisher0.3.01 of 1See more

keptn-cert-manager lifecycle-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
stdlib@go1.23.3
1.25.13

Open the chart page →

513
keptn-lifecycle-operatorlifecycle-toolkitVerified publisher0.6.01 of 1See more

keptn-lifecycle-operator lifecycle-toolkit 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
stdlib@go1.23.3
1.25.13

Open the chart page →

627
keptn-metrics-operatorlifecycle-toolkitVerified publisher0.5.01 of 1See more

keptn-metrics-operator lifecycle-toolkit 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
stdlib@go1.23.3
1.25.13

Open the chart page →

846
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.25.13

Open the chart page →

4,598
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.25.13
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
stdlib@go1.20.7
1.25.13

Open the chart page →

4,419
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
stdlib@go1.23.8
1.25.13

Open the chart page →

8,702
go-hello-worldloafoe0.14.01 of 1See more

go-hello-world loafoe 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-hello-world:v2.13.0d3fb171f20e1
stdlib@go1.25.3
1.25.13

Open the chart page →

684
home-assistantloeken-at-homeVerified publisher2026.5.11 of 1See more

home-assistant loeken-at-home 2026.5.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
loeken/home-assistant:2026.5.14ce6abc553b3
stdlib@go1.23.3
1.25.13

Open the chart page →

3,569
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
stdlib@go1.17.13
1.25.13

Open the chart page →

2,349
vcluster-eksloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-eks loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
stdlib@go1.16.15
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.25.13

Open the chart page →

3,317
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
stdlib@go1.19.4
1.25.13

Open the chart page →

3,168
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
stdlib@go1.17.6
1.25.13

Open the chart page →

1,952
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
stdlib@go1.16.2
1.25.13

Open the chart page →

2,959
lokxylokxyVerified publisher0.2.01 of 1See more

lokxy lokxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
lokxy/lokxy:v0.9.0e4ac800dc55d
stdlib@go1.26.4
1.25.13

Open the chart page →

203
plexluiscajl1.0.11 of 2See more

plex luiscajl 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
linuxserver/plex:latest1f6f97d76e7b
stdlib@go1.26.5
1.25.13

Open the chart page →

783
voice-biometricslumenvox2.0.18 of 26See more

voice-biometrics lumenvox 2.0.1

8 of the 26 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
library/traefik:v2.57d5a6ae66572
stdlib@go1.17.6
1.25.13
lumenvox/cloud-init-tools:2.0.07ff037a71c50
stdlib@go1.17.3
1.25.13
lumenvox/cloud-license:2.0.09a69862e1248
stdlib@go1.17.3
1.25.13
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.13
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.13
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.13
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.13

Open the chart page →

73,751
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.12.0ecba7360ff12
stdlib@go1.25.0
1.25.13

Open the chart page →

1,637
lynqlynqVerified publisher1.1.221 of 1See more

lynq lynq 1.1.22

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/k8s-lynq/lynq:1.1.22229b05e3c717
stdlib@go1.24.13
1.25.13

Open the chart page →

632
magentomagento3.2.35 of 12See more

magento magento 3.2.3

5 of the 12 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.25.13
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.25.13
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
stdlib@go1.24.6
1.25.13
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
stdlib@go1.24.6
1.25.13
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.13

Open the chart page →

14,632
mcp-orchestratormagertronVerified publisher4.0.01 of 7See more

mcp-orchestrator magertron 4.0.0

1 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.25.13

Open the chart page →

1,560
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
stdlib@go1.16.6
1.25.13

Open the chart page →

1,992
plane-enterprisemakeplaneOfficialVerified publisher3.10.22 of 13See more

plane-enterprise makeplane 3.10.2

2 of the 13 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.25.13
pgsty/minio:RELEASE.2026-08-04T00-00-00Zb6bfe7239bfc
stdlib@go1.26.5
1.25.13

Open the chart page →

4,751
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.13

Open the chart page →

20,073
mcpmcp-chartsVerified publisher0.0.232 of 7See more

mcp mcp-charts 0.0.23

2 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
stdlib@go1.25.4
1.25.13
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
stdlib@go1.25.4
1.25.13

Open the chart page →

7,791
mend-renovate-enterprise-editionmend-renovateVerified publisher10.6.01 of 2See more

mend-renovate-enterprise-edition mend-renovate 10.6.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/mend/renovate-ee-server:15.6.087b77989f48d
stdlib@go1.26.4
1.25.13

Open the chart page →

37,489
traefik-forward-authmesosphere0.3.102 of 2See more

traefik-forward-auth mesosphere 0.3.10

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
stdlib@go1.15.11
1.25.13
mesosphere/traefik-forward-auth:3.1.05456581d7b76
stdlib@go1.14.15
1.25.13

Open the chart page →

5,261
metadata-injectormetadata-injector-operator0.0.11 of 1See more

metadata-injector metadata-injector-operator 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ruslanguns/metadata-injector-operator:v0.0.16c77e4675e07
stdlib@go1.22.11
1.25.13

Open the chart page →

591
metrics-server-exportermetrics-server-exporterVerified publisher2.4.01 of 1See more

metrics-server-exporter metrics-server-exporter 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
mrnim94/metrics-server-exporter:v2.4.086c4807a4bca
stdlib@go1.26.3
1.25.13

Open the chart page →

1,322
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
stdlib@go1.14.6
1.25.13

Open the chart page →

3,253
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
stdlib@go1.23.4
1.25.13

Open the chart page →

4,557
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
stdlib@go1.16.12
1.25.13

Open the chart page →

9,072
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
stdlib@go1.17.8
1.25.13

Open the chart page →

3,180
minecraft-exporterminecraft-exporterVerified publisher0.16.01 of 1See more

minecraft-exporter minecraft-exporter 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
stdlib@go1.25.10
1.25.13

Open the chart page →

355
miniapiminiapi1.3.21 of 1See more

miniapi miniapi 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
udhos/miniapi:1.3.28a7042db82ce
stdlib@go1.23.2
1.25.13

Open the chart page →

879
miropsmirops-operatorVerified publisher0.2.02 of 2See more

mirops mirops-operator 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/miropshq/mirops/operator:v0.2.04b0b5fef9a6a
stdlib@go1.24.13
1.25.13
ghcr.io/miropshq/mirops/remediation:v0.2.0976a7319ff4a
stdlib@go1.24.13
1.25.13

Open the chart page →

1,051
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.13

Open the chart page →

6,398
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
stdlib@go1.25.4
1.25.13

Open the chart page →

36,527
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
stdlib@go1.24.0
1.25.13

Open the chart page →

3,017
model-manager-servermodel-manager-server1.27.01 of 1See more

model-manager-server model-manager-server 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
stdlib@go1.23.12
1.25.13

Open the chart page →

744
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.13

Open the chart page →

14,675
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:1886c951e05bf5
stdlib@go1.24.6
1.25.13
library/redmine:6.1.204ac44a2595b
stdlib@go1.24.6
1.25.13

Open the chart page →

8,071
podsyncmy0nVerified publisher1.5.41 of 2See more

podsync my0n 1.5.4

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
tdeutsch/podsync:v2.4.2b67186f4c9a5
stdlib@go1.19.3
1.25.13

Open the chart page →

2,065
maddymyaVerified publisher22.4.121 of 2See more

maddy mya 22.4.12

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
foxcpp/maddy:0.7.16ab538e2f28b
stdlib@go1.19.13
1.25.13

Open the chart page →

1,422
registrymyaVerified publisher22.4.111 of 1See more

registry mya 22.4.11

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
distribution/distribution:2.8.3f84b2078238f
stdlib@go1.20.8
1.25.13

Open the chart page →

902
simple-gowikimy-helm-chartsVerified publisher0.2.01 of 1See more

simple-gowiki my-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
forchaladtest/mygowiki:1.0.170827eaecad1
stdlib@go1.22.6
1.25.13

Open the chart page →

402
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
stdlib@go1.18.1
1.25.13

Open the chart page →

3,940

Container images carrying it

5,367 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.