StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,688
of 17,985 indexed, latest versions
Container images
5,349
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,688 of 17,985 indexed charts deploy, on 5,349 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,349
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,688 by stars
ChartLatestAffected imagesRadar Score
fission-allfission-chartsOfficialVerified publisher1.27.03 of 3See more

fission-all fission-charts 1.27.0

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/fission/fission-bundle:v1.27.0d353720b037a
stdlib@go1.26.4
1.25.13
ghcr.io/fission/pre-upgrade-checks:v1.27.0b053fc3539b4
stdlib@go1.26.4
1.25.13
ghcr.io/fission/reporter:v1.27.0c77cc925debe
stdlib@go1.26.4
1.25.13

Open the chart page →

559
rancherrancher-latest2.15.21 of 2See more

rancher rancher-latest 2.15.2

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.20c3d8e570255
stdlib@go1.26.4
1.25.13

Open the chart page →

2,172
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.25.13
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.25.13

Open the chart page →

6,853
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
stdlib@go1.24.6
1.25.13

Open the chart page →

930
mariadbcloudpirates-mariadbVerified publisher0.16.151 of 1See more

mariadb cloudpirates-mariadb 0.16.15

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mariadb:13.0.2d4fdec0510ad
stdlib@go1.24.6
1.25.13

Open the chart page →

1,833
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.25.13
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
stdlib@go1.25.5
1.25.13
langgenius/dify-sandbox:0.2.124e65e8a351a2
stdlib@go1.23.3
1.25.13
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.25.13

Open the chart page →

82,283
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.4.02 of 3See more

kubeshark kubeshark-helm-charts 53.4.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
kubeshark/hub:v53.46d3f22525a0e
stdlib@go1.26.5
1.25.13
kubeshark/worker:v53.4b226490dfa11
stdlib@go1.26.5
1.25.13

Open the chart page →

1,128
secrets-store-csi-driversecret-store-csi-driver1.6.13 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

3 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
stdlib@go1.25.7
1.25.13

Open the chart page →

2,398
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.31 of 2See more

stackgres-operator stackgres-charts 1.19.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
stdlib@go1.20.10
1.25.13

Open the chart page →

2,866
mongodbcloudpirates-mongodbVerified publisher0.19.01 of 1See more

mongodb cloudpirates-mongodb 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
stdlib@go1.26.5
1.25.13

Open the chart page →

1,279
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
stdlib@go1.16.4
1.25.13

Open the chart page →

17,902
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
stdlib@go1.26.4
1.25.13

Open the chart page →

586
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.25.13

Open the chart page →

2,038
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
stdlib@go1.25.7
1.25.13
grafana/grafana:12.4.1e932bd6ed0e0
stdlib@go1.25.8
1.25.13
rancher/kubectl:v1.25.085a0d1148784
stdlib@go1.19
1.25.13
victoriametrics/operator:v0.68.3f52e1bd679cb
stdlib@go1.25.8
1.25.13
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
stdlib@go1.25.3
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.13

Open the chart page →

12,333
miniocloudpirates-minioVerified publisher0.14.01 of 1See more

minio cloudpirates-minio 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
stdlib@go1.25.7
1.25.13

Open the chart page →

1,577
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
stdlib@go1.21.8
1.25.13
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
stdlib@go1.24.6
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
stdlib@go1.24.6
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
stdlib@go1.24.6
1.25.13

Open the chart page →

8,465
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.25.13
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.25.13
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.25.13
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.25.13
langgenius/dify-sandbox:0.2.15750e1111426e
stdlib@go1.24.13
1.25.13

Open the chart page →

72,676
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
stdlib@go1.26.5
1.25.13

Open the chart page →

1,031
pyroscopegrafana2.3.12 of 3See more

pyroscope grafana 2.3.1

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
stdlib@go1.25.5
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.13

Open the chart page →

4,067
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
stdlib@go1.21.13
1.25.13

Open the chart page →

1,461
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
stdlib@go1.24.2
1.25.13

Open the chart page →

1,207
thanosthanos-communityOfficialVerified publisher0.46.01 of 1See more

thanos thanos-community 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
stdlib@go1.26.5
1.25.13

Open the chart page →

301
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:18-alpine6c538e7206ea
stdlib@go1.24.6
1.25.13

Open the chart page →

2,287
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
stdlib@go1.15
1.25.13

Open the chart page →

5,438
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
stdlib@go1.26.5
1.25.13

Open the chart page →

159
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6446551b26c0b
stdlib@go1.22.2
1.25.13

Open the chart page →

1,205
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
stdlib@go1.25.12
1.25.13

Open the chart page →

94
kiali-serverkiali2.32.01 of 1See more

kiali-server kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.32.0b171d679be27
stdlib@go1.26.3
1.25.13

Open the chart page →

350
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
stdlib@go1.25.12
1.25.13

Open the chart page →

982
vela-corekubevela1.11.03 of 3See more

vela-core kubevela 1.11.0

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
oamdev/cluster-gateway:v1.9.0-alpha.25591e29d66a2
stdlib@go1.19.8
1.25.13
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
stdlib@go1.17.11
1.25.13
oamdev/vela-core:v1.11.095fa412c934e
stdlib@go1.23.8
1.25.13

Open the chart page →

6,278
oktetooktetoOfficialVerified publisher0.0.0-2026-08-316 of 10See more

okteto okteto 0.0.0-2026-08-31

6 of the 10 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-316171cb2b2a72
stdlib@go1.25.12
1.25.13
ghcr.io/okteto/buildkit:0.0.0-2026-08-3114527ca5d2a9
stdlib@go1.25.7
1.25.13
ghcr.io/okteto/daemon:0.0.0-2026-08-31c6e716a3fbbe
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/okteto:3.23.0-beta.1a0483d47ba04
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/registry:0.0.0-2026-08-3169131511501f
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/reloader:0.0.0-2026-08-3104a3fce657c4
stdlib@go1.26.4
1.25.13

Open the chart page →

6,765
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
stdlib@go1.26.0
1.25.13
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
stdlib@go1.26.3
1.25.13

Open the chart page →

1,742
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
stdlib@go1.24.9
1.25.13

Open the chart page →

1,219
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
stdlib@go1.26.5
1.25.13
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
stdlib@go1.26.3
1.25.13

Open the chart page →

2,690
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
stdlib@go1.26.5
1.25.13

Open the chart page →

2,074
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
stdlib@go1.25.11
1.25.13

Open the chart page →

1,707
concourseconcourseVerified publisher20.3.11 of 2See more

concourse concourse 20.3.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.25.13

Open the chart page →

1,905
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
stdlib@go1.16.8
1.25.13

Open the chart page →

5,196
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
stdlib@go1.23.4
1.25.13

Open the chart page →

2,310
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
stdlib@go1.22.4
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
stdlib@go1.17.8
1.25.13
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
stdlib@go1.17.8
1.25.13
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
stdlib@go1.17.8
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
stdlib@go1.17.8
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
stdlib@go1.18.2
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
stdlib@go1.16.9
1.25.13

Open the chart page →

22,347
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
stdlib@go1.26.5
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.13

Open the chart page →

1,404
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
stdlib@go1.26.3
1.25.13

Open the chart page →

356
openbaoopenbaoVerified publisher0.30.11 of 2See more

openbao openbao 0.30.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
stdlib@go1.25.5
1.25.13

Open the chart page →

1,448
openprojectopenproject-helm-chartsOfficialVerified publisher13.13.11 of 5See more

openproject openproject-helm-charts 13.13.1

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.25.13

Open the chart page →

20,878
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
stdlib@go1.26.0
1.25.13

Open the chart page →

1,119
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
stdlib@go1.25.12
1.25.13

Open the chart page →

1,545
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
stdlib@go1.14.12
1.25.13

Open the chart page →

13,468
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
stdlib@go1.21.5
1.25.13

Open the chart page →

2,035
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
stdlib@go1.24.6
1.25.13
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
stdlib@go1.18.1
1.25.13
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.25.13

Open the chart page →

37,046
chatwootchatwootVerified publisher2.0.272 of 3See more

chatwoot chatwoot 2.0.27

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.25.13
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.25.13

Open the chart page →

8,490

Container images carrying it

5,349 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.