StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,712
of 17,966 indexed, latest versions
Container images
5,376
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,712 of 17,966 indexed charts deploy, on 5,376 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,376
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,712 by stars
ChartLatestAffected imagesRadar Score
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
stdlib@go1.16.10
1.25.13

Open the chart page →

2,809
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
stdlib@go1.15.8
1.25.13

Open the chart page →

2,186
ai-scale-saverdysnixVerified publisher0.1.01 of 1See more

ai-scale-saver dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alex6021710/ai-scale-saver:latestf73e8d60fd03
stdlib@go1.17
1.25.13

Open the chart page →

2,143
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
stdlib@go1.21.10
1.25.13

Open the chart page →

9,768
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
stdlib@go1.22.2
1.25.13

Open the chart page →

2,175
bordysnixVerified publisher0.0.81 of 1See more

bor dysnix 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
0xpolygon/bor:1.3.7396d3de26d8b
stdlib@go1.22.1
1.25.13

Open the chart page →

1,391
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.13

Open the chart page →

2,389
gke-upgrade-notification-handlerdysnixVerified publisher0.1.11 of 1See more

gke-upgrade-notification-handler dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
stdlib@go1.17.7
1.25.13

Open the chart page →

2,108
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:7.4.5d322192ed2fa
stdlib@go1.15.6
1.25.13

Open the chart page →

5,210
heimdalldysnixVerified publisher0.0.11 of 1See more

heimdall dysnix 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
0xpolygon/heimdall:1.0.134ddf259993c
stdlib@go1.20.5
1.25.13

Open the chart page →

1,373
local-path-provisionerdysnixVerified publisher0.0.201 of 1See more

local-path-provisioner dysnix 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
stdlib@go1.16.6
1.25.13

Open the chart page →

2,922
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.25.13

Open the chart page →

4,948
servicemonitor-appsdysnixVerified publisher0.1.01 of 1See more

servicemonitor-apps dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
stdlib@go1.18.10
1.25.13

Open the chart page →

1,576
smokeping-proberdysnixVerified publisher0.3.11 of 1See more

smokeping-prober dysnix 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
superque/smokeping-prober:v0.11.028ca636d1dee
stdlib@go1.26.1
1.25.13

Open the chart page →

464
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
stdlib@go1.13.10
1.25.13

Open the chart page →

7,293
echoappechoapp0.1.01 of 1See more

echoapp echoapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hashicorp/http-echo:1.0.0fcb75f691c8b
stdlib@go1.21.1
1.25.13

Open the chart page →

553
aeros-orchestrator-overlayeclipse-aeriosVerified publisher2.0.01 of 2See more

aeros-orchestrator-overlay eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
masipcat/wireguard-go:latest696206e5954d
stdlib@go1.20.14
1.25.13

Open the chart page →

1,190
api-gatewayeclipse-aeriosVerified publisher1.7.01 of 1See more

api-gateway eclipse-aerios 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.6.34c678c224f67
stdlib@go1.22.3
1.25.13

Open the chart page →

1,448
federatoreclipse-aeriosVerified publisher1.1.01 of 1See more

federator eclipse-aerios 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eclipseaerios/federator:1.1.018c7f0d101c0
stdlib@go1.22.12
1.25.13

Open the chart page →

739
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.25.13

Open the chart page →

5,008
iotaeclipse-aeriosVerified publisher1.0.23 of 4See more

iota eclipse-aerios 1.0.2

3 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eclipseaerios/iota-tangle-peerer:latest99d7ff18d416
stdlib@go1.22.12
1.25.13
iotaledger/hornet:2.001206f1ba89c
stdlib@go1.21.10
1.25.13
iotaledger/inx-dashboard:1.012c669cb8748
stdlib@go1.21.1
1.25.13

Open the chart page →

14,448
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
stdlib@go1.21.13
1.25.13

Open the chart page →

927
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
stdlib@go1.23.12
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
stdlib@go1.19.4
1.25.13

Open the chart page →

2,192
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
stdlib@go1.21.13
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
stdlib@go1.19.4
1.25.13

Open the chart page →

2,172
llo-natseclipse-aeriosVerified publisher1.0.01 of 1See more

llo-nats eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/nats:2.11.4c8cd23806eef
stdlib@go1.24.3
1.25.13

Open the chart page →

848
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.25.13

Open the chart page →

11,726
openfaas2eclipse-aeriosVerified publisher12.0.56 of 6See more

openfaas2 eclipse-aerios 12.0.5

6 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.5ced93c701875
stdlib@go1.19.10
1.25.13
prom/prometheus:v2.51.24f6c47e39a90
stdlib@go1.22.2
1.25.13
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
stdlib@go1.23.4
1.25.13
ghcr.io/openfaas/gateway:0.27.1382b15393116e
stdlib@go1.24.6
1.25.13
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
stdlib@go1.22.1
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.13

Open the chart page →

6,984
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.25.13

Open the chart page →

7,560
orion-ldeclipse-aeriosVerified publisher1.0.01 of 2See more

orion-ld eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.21.12
1.25.13

Open the chart page →

10,130
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
stdlib@go1.16.6
1.25.13

Open the chart page →

2,815
edge-accessedge-accessVerified publisher0.1.01 of 1See more

edge-access edge-access 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
stdlib@go1.25.4
1.25.13

Open the chart page →

676
continuum-proxyedgelesssysVerified publisher1.5.11 of 1See more

continuum-proxy edgelesssys 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/continuum/continuum-proxydigest-pinned24c76f294a80
stdlib@go1.23.3
1.25.13

Open the chart page →

860
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
stdlib@go1.26.1
1.25.13

Open the chart page →

2,023
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
stdlib@go1.16.7
1.25.13

Open the chart page →

11,328
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,785
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.13

Open the chart page →

3,201
prometheusedu11.6.04 of 6See more

prometheus edu 11.6.0

4 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.25.13
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.25.13
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.13
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.13

Open the chart page →

8,487
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
stdlib@go1.13.10
1.25.13

Open the chart page →

7,365
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
stdlib@go1.22.8
1.25.13

Open the chart page →

1,328
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
stdlib@go1.23.3
1.25.13

Open the chart page →

2,617
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.13

Open the chart page →

7,929
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.25.13

Open the chart page →

33,386
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
stdlib@go1.24.4
1.25.13
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
stdlib@go1.24.4
1.25.13

Open the chart page →

4,362
eg-universal-agent-operatoreg-universal-agent-operatorVerified publisher0.0.51 of 1See more

eg-universal-agent-operator eg-universal-agent-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
stdlib@go1.24.6
1.25.13

Open the chart page →

594
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
stdlib@go1.13.10
1.25.13

Open the chart page →

7,568
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
stdlib@go1.23.6
1.25.13

Open the chart page →

910
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.13

Open the chart page →

8,232
eks-auto-pod-id-assoceks-auto-pod-id-assoc0.6.01 of 1See more

eks-auto-pod-id-assoc eks-auto-pod-id-assoc 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
udhos/eks-auto-pod-id-assoc:0.6.0196ef68af380
stdlib@go1.26.3
1.25.13

Open the chart page →

965
postgresqleks-storageclass0.1.01 of 1See more

postgresql eks-storageclass 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
stdlib@go1.24.6
1.25.13

Open the chart page →

1,446
elastic-agentelasticVerified publisher9.5.41 of 2See more

elastic-agent elastic 9.5.4

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
stdlib@go1.24.4
1.25.13

Open the chart page →

767

Container images carrying it

5,376 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.