StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,700
of 17,985 indexed, latest versions
Container images
5,367
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,700 of 17,985 indexed charts deploy, on 5,367 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,367
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,700 by stars
ChartLatestAffected imagesRadar Score
periscopeperiscopeVerified publisher1.1.61 of 1See more

periscope periscope 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
stdlib@go1.26.4
1.25.13

Open the chart page →

969
pgbouncerpgbouncer-helm0.6.01 of 2See more

pgbouncer pgbouncer-helm 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.25.13

Open the chart page →

475
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
stdlib@go1.20.1
1.25.13
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
stdlib@go1.20.1
1.25.13
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
stdlib@go1.20.1
1.25.13
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
stdlib@go1.20.1
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.25.13

Open the chart page →

7,283
full-housephilmtd1.3.21 of 1See more

full-house philmtd 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
philmtd/full-house:1.10.0224d602420ba
stdlib@go1.26.3
1.25.13

Open the chart page →

93
chadbotphntom0.2.31 of 1See more

chadbot phntom 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
phntom/chadbot:0.2.397c28e4178ad
stdlib@go1.21.5
1.25.13

Open the chart page →

1,099
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
stdlib@go1.19.3
1.25.13

Open the chart page →

2,950
phonebook-chartphonebook-chart0.1.01 of 3See more

phonebook-chart phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

3,048
phpipamphpipam-helmVerified publisher1.0.121 of 3See more

phpipam phpipam-helm 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.25.13

Open the chart page →

3,880
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
stdlib@go1.15.8
1.25.13

Open the chart page →

2,117
matomopockostVerified publisher1.4.01 of 3See more

matomo pockost 1.4.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
stdlib@go1.24.6
1.25.13

Open the chart page →

5,703
podtracepodtraceOfficialVerified publisher0.14.81 of 2See more

podtrace podtrace 0.14.8

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/k8s:1.37.0b421c2e9419e
stdlib@go1.26.5
1.25.13

Open the chart page →

682
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Open the chart page →

2,213
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.25.13
treskon/portrait:DEV-latest88e813f22347
stdlib@go1.26.5
1.25.13

Open the chart page →

34,487
postfix-exporterpostfix-exporterVerified publisher0.2.01 of 1See more

postfix-exporter postfix-exporter 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/hsn723/postfix_exporter:0.20.0b7da7c554018
stdlib@go1.26.2
1.25.13

Open the chart page →

413
postgres-backuppostgres-backup0.3.02 of 2See more

postgres-backup postgres-backup 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.13
nerzhul/mc-arm64:2020.10.034215df511f31
stdlib@go1.15.2
1.25.13

Open the chart page →

5,471
postgresqlpostgresqlVerified publisher0.3.172 of 2See more

postgresql postgresql 0.3.17

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:18.6-alpine77f585114c32
stdlib@go1.24.6
1.25.13
pgautoupgrade/pgautoupgrade:18-alpine2245aabc5b80
stdlib@go1.24.6
1.25.13

Open the chart page →

648
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.13

Open the chart page →

1,460
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
stdlib@go1.16.9
1.25.13

Open the chart page →

2,909
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.13

Open the chart page →

2,887
home-assistantpree-helm-chartsVerified publisher1.82.01 of 1See more

home-assistant pree-helm-charts 1.82.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.43e6710a7ab2a
stdlib@go1.23.3
1.25.13

Open the chart page →

2,605
preparrpreparr0.19.71 of 6See more

preparr preparr 0.19.7

1 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.25.13

Open the chart page →

950
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.25.13

Open the chart page →

5,959
projectionprojectionVerified publisher0.3.21 of 1See more

projection projection 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/projection-operator/projection:0.3.2d06374430a17
stdlib@go1.26.3
1.25.13

Open the chart page →

225
prometheus-druid-exporterprometheus-communityVerified publisher1.2.01 of 1See more

prometheus-druid-exporter prometheus-community 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.25.13

Open the chart page →

1,182
prometheus-pingmesh-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-pingmesh-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
stdlib@go1.22.9
1.25.13

Open the chart page →

857
prometheus-sql-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-sql-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
stdlib@go1.24.4
1.25.13

Open the chart page →

1,469
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.13
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.25.13
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.13
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.13
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.25.13

Open the chart page →

9,945
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
stdlib@go1.26.3-X:jsonv2
1.25.13

Open the chart page →

9,573
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
stdlib@go1.22.0
1.25.13

Open the chart page →

724
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
stdlib@go1.19
1.25.13

Open the chart page →

1,659
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.26.4
1.25.13

Open the chart page →

61,276
qt-vaultqt-vaultVerified publisher0.1.21 of 1See more

qt-vault qt-vault 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/mcman2017/qt-vault:v0.1.2852edf54c850
stdlib@go1.24.11
1.25.13

Open the chart page →

309
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
stdlib@go1.19.4
1.25.13

Open the chart page →

7,152
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.25.13

Open the chart page →

3,122
kube-images-syncraczylo-comVerified publisher0.5.571 of 1See more

kube-images-sync raczylo-com 0.5.57

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/lukaszraczylo/kubernetes-images-sync-operator:0.5.57a424948c8143
stdlib@go1.25.5
1.25.13

Open the chart page →

423
velero-s3-deploymentradar-baseVerified publisher0.4.33 of 4See more

velero-s3-deployment radar-base 0.4.3

3 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
stdlib@go1.18
1.25.13
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
stdlib@go1.17.11
1.25.13
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
stdlib@go1.23.4
1.25.13

Open the chart page →

4,840
rbac-serverrbac-server1.19.11 of 1See more

rbac-server rbac-server 1.19.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
stdlib@go1.23.12
1.25.13

Open the chart page →

706
rclonercloneVerified publisher2.2.01 of 1See more

rclone rclone 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
stdlib@go1.23.3
1.25.13

Open the chart page →

1,675
redis-enterprise-operatorredis-enterprise-operatorVerified publisher7.13.4-121 of 1See more

redis-enterprise-operator redis-enterprise-operator 7.13.4-12

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
redislabs/operator:7.4.2-2ecb101af0506
stdlib@go1.21.5
1.25.13

Open the chart page →

2,707
redis-chartredis-ha-chartVerified publisher0.1.51 of 2See more

redis-chart redis-ha-chart 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
truebyteinnovationllp/redis-exporter:v1.86.01c6a945af653
stdlib@go1.25.11
1.25.13

Open the chart page →

325
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
stdlib@go1.22.6
1.25.13

Open the chart page →

2,894
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.25.13

Open the chart page →

4,892
docker-registry-mirrorregistry-mirror1.0.11 of 1See more

docker-registry-mirror registry-mirror 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.25.13

Open the chart page →

553
reportportalreportportal-ioOfficialVerified publisher26.8.127 of 15See more

reportportal reportportal-io 26.8.12

7 of the 15 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
stdlib@go1.24.2
1.25.13
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.13
library/rabbitmq:4.3.4-managementeb5295d08332
stdlib@go1.22.2
1.25.13
rancher/kubectl:v1.36.206c7a7a97727
stdlib@go1.26.4
1.25.13
reportportal/k8s-wait-for:latest06cdf299b397
stdlib@go1.26.4
1.25.13
reportportal/migrations:5.15.4464468240d7b
stdlib@go1.24.6
1.25.13
reportportal/service-index:5.15.1b1860ed33071
stdlib@go1.26.2
1.25.13

Open the chart page →

13,664
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.25.13

Open the chart page →

6,844
resurfaceresurfaceioVerified publisher3.9.02 of 3See more

resurface resurfaceio 3.9.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
stdlib@go1.22.2
1.25.13
resurfaceio/resurface:3.7.84d5cda2f64109
stdlib@go1.23.0
1.25.13

Open the chart page →

7,850
retyc-csiretyc-csi0.2.02 of 3See more

retyc-csi retyc-csi 0.2.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.13

Open the chart page →

1,641
right-sizerright-sizer0.6.21 of 1See more

right-sizer right-sizer 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
aavishay/right-sizer:0.6.23d7c4d79595c
stdlib@go1.25.8
1.25.13

Open the chart page →

298
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
stdlib@go1.17.13
1.25.13

Open the chart page →

2,058
rke2-ingress-nginxrke2-charts4.15.1102 of 2See more

rke2-ingress-nginx rke2-charts 4.15.110

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rancher/kube-webhook-certgen:v1.14.5-hardened26bb869baf40b
stdlib@go1.26.2
1.25.13
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
stdlib@go1.24.13
1.25.13

Open the chart page →

889

Container images carrying it

5,367 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.