StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,700
of 17,985 indexed, latest versions
Container images
5,367
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,700 of 17,985 indexed charts deploy, on 5,367 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,367
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,700 by stars
ChartLatestAffected imagesRadar Score
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.25.13

Open the chart page →

9,727
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.25.13

Open the chart page →

4,431
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.25.13

Open the chart page →

13,890
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.25.13

Open the chart page →

10,550
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
stdlib@go1.18.6
1.25.13
kong/kubernetes-ingress-controller:2.35e66021b64a8
stdlib@go1.18
1.25.13

Open the chart page →

91,726
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
stdlib@go1.17.12
1.25.13
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.13
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
stdlib@go1.18.3
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
stdlib@go1.18.5
1.25.13

Open the chart page →

8,585
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

8,243
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.25.13
devopsfaith/krakend:latestf8bdaa8a1a43
stdlib@go1.24.2
1.25.13
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.13
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

47,855
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.25.13
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
stdlib@go1.23.1
1.25.13
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
stdlib@go1.23.1
1.25.13
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.25.13

Open the chart page →

34,361
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
stdlib@go1.24.6
1.25.13
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
stdlib@go1.24.7
1.25.13

Open the chart page →

3,386
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
stdlib@go1.24.7
1.25.13

Open the chart page →

1,551
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.25.13

Open the chart page →

1,760
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
stdlib@go1.22.12
1.25.13

Open the chart page →

4,268
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
stdlib@go1.22.12
1.25.13

Open the chart page →

4,268
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
stdlib@go1.22.12
1.25.13

Open the chart page →

4,188
graph-nodeastria0.2.23 of 3See more

graph-node astria 0.2.2

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
graphprotocol/graph-node:latestb0436347fb24
stdlib@go1.26.5
1.25.13
ipfs/kubo:v0.17.0803fac58ba15
stdlib@go1.19.1
1.25.13
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.13

Open the chart page →

5,566
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
stdlib@go1.22.11
1.25.13
rclone/rclone:1.56.0f2fc45c8bc57
stdlib@go1.16.6
1.25.13

Open the chart page →

6,817
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
stdlib@go1.22.6
1.25.13

Open the chart page →

1,339
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

3,192
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
stdlib@go1.18.10
1.25.13

Open the chart page →

9,976
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
stdlib@go1.15.3
1.25.13
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.25.13

Open the chart page →

6,539
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1147d6dadc050e
stdlib@go1.22.2
1.25.13

Open the chart page →

1,709
alertmanager-discordatrox3.1.01 of 1See more

alertmanager-discord atrox 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.25.13

Open the chart page →

590
attestkeepattestkeepVerified publisher1.3.02 of 2See more

attestkeep attestkeep 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:16.15-alpine721873c34ceb
stdlib@go1.24.6
1.25.13
ghcr.io/attestkeep/attestkeep-k8s:1.3.0a3813ac7b8f2
stdlib@go1.26.4
1.25.13

Open the chart page →

553
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
stdlib@go1.13.10
1.25.13

Open the chart page →

7,620
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.25.13

Open the chart page →

1,733
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
stdlib@go1.19.7
1.25.13

Open the chart page →

5,206
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
stdlib@go1.19.3
1.25.13

Open the chart page →

7,156
kubeslice-workeraveshaVerified publisher1.5.02 of 14See more

kubeslice-worker avesha 1.5.0

2 of the 14 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
stdlib@go1.22.2
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
stdlib@go1.20.3
1.25.13

Open the chart page →

1,664
amazon-ec2-metadata-mockaws1.11.21 of 1See more

amazon-ec2-metadata-mock aws 1.11.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
stdlib@go1.17.13
1.25.13

Open the chart page →

864
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
stdlib@go1.17.3
1.25.13

Open the chart page →

2,492
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.25.13

Open the chart page →

2,797
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
stdlib@go1.19.3
1.25.13
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
stdlib@go1.19.3
1.25.13

Open the chart page →

2,977
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
stdlib@go1.15.3
1.25.13

Open the chart page →

2,136
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
stdlib@go1.21.2
1.25.13

Open the chart page →

9,968
axonops-developer-operatoraxonops-developer-operator0.1.01 of 1See more

axonops-developer-operator axonops-developer-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
stdlib@go1.22.10
1.25.13

Open the chart page →

745
axonops-operatoraxonops-operator0.1.01 of 1See more

axonops-operator axonops-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-operator:0.1.0e0cdb993f0b1
stdlib@go1.25.9
1.25.13

Open the chart page →

320
azerothcoreazerothcoreVerified publisher0.1.12 of 6See more

azerothcore azerothcore 0.1.1

2 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/k8s:1.35.8aaeed1de1399
stdlib@go1.26.5
1.25.13
library/mysql:8.4.116ea90827b110
stdlib@go1.24.6
1.25.13

Open the chart page →

107,594
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
stdlib@go1.17.9
1.25.13

Open the chart page →

4,676
azurefile-csi-driverazurefile-csi-driverVerified publisher1.35.71 of 7See more

azurefile-csi-driver azurefile-csi-driver 1.35.7

1 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.7c3c80b940df6
stdlib@go1.25.11
1.25.13

Open the chart page →

861
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
stdlib@go1.15
1.25.13

Open the chart page →

5,652
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
stdlib@go1.15.10
1.25.13
fluxcd/source-controller:v0.10.031a8c79a6803
stdlib@go1.15.10
1.25.13

Open the chart page →

7,697
keptn-addonsazureorkestra0.1.04 of 4See more

keptn-addons azureorkestra 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
keptn/distributor:0.8.36bc3df9e0d6a
stdlib@go1.16.2
1.25.13
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.25.13
keptncontrib/prometheus-service:0.6.029969dd547de
stdlib@go1.13.7
1.25.13
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
stdlib@go1.16.2
1.25.13

Open the chart page →

10,623
prometheusazureorkestra14.8.05 of 6See more

prometheus azureorkestra 14.8.0

5 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.13
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.13
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.13
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.13

Open the chart page →

9,668
webserverazureorkestra1.0.01 of 1See more

webserver azureorkestra 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
nmalhotr/webserver:v1.0.03419361fb0dd
stdlib@go1.13.10
1.25.13

Open the chart page →

3,356
krakendbaboulinet0.1.341 of 1See more

krakend baboulinet 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.7.09219cda867e2
stdlib@go1.22.5
1.25.13

Open the chart page →

1,343
ragflowbaboulinet0.1.12 of 5See more

ragflow baboulinet 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.25.13
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
stdlib@go1.21.5
1.25.13

Open the chart page →

6,195
prometheus-blackbox-exporterbackbox-exporter7.8.01 of 1See more

prometheus-blackbox-exporter backbox-exporter 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.23.0ca04aa9d9093
stdlib@go1.19.3
1.25.13

Open the chart page →

1,501
backlokto-operatorbacklokto0.0.11 of 1See more

backlokto-operator backlokto 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
piblokto/backlokto-operator:v0.0.20963cda71e393
stdlib@go1.20.14
1.25.13

Open the chart page →

700
backrestbackrest0.2.01 of 1See more

backrest backrest 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
garethgeorge/backrest:latestb85297975428
stdlib@go1.26.0
1.25.13

Open the chart page →

913

Container images carrying it

5,367 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.