StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,707
of 17,957 indexed, latest versions
Container images
5,361
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,707 of 17,957 indexed charts deploy, on 5,361 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,361
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,707 by stars
ChartLatestAffected imagesRadar Score
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.13

Open the chart page →

4,396
apimicroslacVerified publisher0.1.01 of 2See more

api microslac 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.1999213b98257
stdlib@go1.21.9
1.25.13

Open the chart page →

3,520
argomicroslacVerified publisher0.1.03 of 4See more

argo microslac 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.13
ghcr.io/dexidp/dex:v2.38.0b1d793440a98
stdlib@go1.21.6
1.25.13
quay.io/argoproj/argocd:v2.10.783c86003b781
stdlib@go1.20.10
1.25.13

Open the chart page →

10,134
streamsmicroslacVerified publisher0.1.01 of 6See more

streams microslac 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
microslac/kafka-connect:latesta90091a1f524
stdlib@go1.20.4
1.25.13

Open the chart page →

20,728
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
stdlib@go1.18.9
1.25.13

Open the chart page →

1,796
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
stdlib@go1.18.10
1.25.13
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
stdlib@go1.18.10
1.25.13
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
stdlib@go1.19.6
1.25.13
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
stdlib@go1.18.10
1.25.13

Open the chart page →

8,409
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
stdlib@go1.18.10
1.25.13
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
stdlib@go1.18.10
1.25.13
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
stdlib@go1.19.7
1.25.13
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
stdlib@go1.18.10
1.25.13

Open the chart page →

8,401
mw-autoinstrumentationmiddleware-labsVerified publisher1.2.65 of 6See more

mw-autoinstrumentation middleware-labs 1.2.6

5 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-auto-injector:0.1.18512248e17e8
stdlib@go1.23.12
1.25.13
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
stdlib@go1.24.0
1.25.13
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
stdlib@go1.23.12
1.25.13
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.132.05e331c925091
stdlib@go1.24.6
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.13

Open the chart page →

3,788
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
stdlib@go1.20.14
1.25.13

Open the chart page →

1,602
mw-kube-agent-v3middleware-labsVerified publisher1.8.62 of 2See more

mw-kube-agent-v3 middleware-labs 1.8.6

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.21.507011b628e6b
stdlib@go1.25.6
1.25.13
ghcr.io/middleware-labs/mw-kube-agent-config-updater:1.21.50a054cedfe30
stdlib@go1.25.6
1.25.13

Open the chart page →

1,343
sshportalmidokura-communityVerified publisher0.1.41 of 2See more

sshportal midokura-community 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
moul/sshportal:v1.19.3332b603727c3
stdlib@go1.17.6
1.25.13

Open the chart page →

2,321
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
stdlib@go1.23.4
1.25.13

Open the chart page →

1,371
imaginemikejohVerified publisher0.2.01 of 1See more

imagine mikejoh 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
mikejoh/imagine:0.1.078737d7345f9
stdlib@go1.23.3
1.25.13

Open the chart page →

562
local-path-provisionermikejohVerified publisher0.0.291 of 1See more

local-path-provisioner mikejoh 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
stdlib@go1.22.5
1.25.13

Open the chart page →

1,315
miniomilvus-helm8.0.211See more

minio milvus-helm 8.0.21

1 container image this version deploys carries CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
stdlib@go1.23.4
1.25.13

Open the chart page →

—
pulsarv2milvus-helm2.7.82 of 4See more

pulsarv2 milvus-helm 2.7.8

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
stdlib@go1.13.10
1.25.13
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
stdlib@go1.13.4
1.25.13

Open the chart page →

15,936
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
stdlib@go1.24.13
1.25.13

Open the chart page →

384
zkapps-dashboardminaVerified publisher0.1.21 of 2See more

zkapps-dashboard mina 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.25.13

Open the chart page →

1,703
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.25.13

Open the chart page →

13,463
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
stdlib@go1.17.4
1.25.13

Open the chart page →

6,136
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.25.13

Open the chart page →

118,232
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.13

Open the chart page →

10,913
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.13

Open the chart page →

10,913
helmmirasys-chart0.1.01 of 4See more

helm mirasys-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.26.5
1.25.13

Open the chart page →

3,824
mitosmitosVerified publisher1.6.05 of 7See more

mitos mitos 1.6.0

5 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/mitos-run/mitos-console:v1.6.0209e966322ab
stdlib@go1.26.4
1.25.13
ghcr.io/mitos-run/mitos-controller:v1.6.0b547c38dcc9d
stdlib@go1.26.4
1.25.13
ghcr.io/mitos-run/mitos-forkd:v1.6.0979b462ab7d6
stdlib@go1.26.4
1.25.13
ghcr.io/mitos-run/mitos-gateway:v1.6.0017274a28204
stdlib@go1.26.4
1.25.13
ghcr.io/mitos-run/mitos-kvm-device-plugin:v1.6.063e2b78d03c4
stdlib@go1.26.4
1.25.13

Open the chart page →

3,206
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
stdlib@go1.21.7
1.25.13

Open the chart page →

1,900
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
stdlib@go1.15.13
1.25.13

Open the chart page →

2,855
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
stdlib@go1.13.14
1.25.13

Open the chart page →

7,928
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
stdlib@go1.18.3
1.25.13

Open the chart page →

1,831
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.25.13

Open the chart page →

10,331
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.25.13

Open the chart page →

7,271
basic-git-servermoikot0.0.21 of 1See more

basic-git-server moikot 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.25.13

Open the chart page →

2,956
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.25.13

Open the chart page →

2,561
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
stdlib@go1.14.13
1.25.13

Open the chart page →

1,748
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
stdlib@go1.14.15
1.25.13

Open the chart page →

1,736
docker-registrymoinologics0.1.11 of 1See more

docker-registry moinologics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.25.13

Open the chart page →

551
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
stdlib@go1.18.7
1.25.13

Open the chart page →

2,484
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.13

Open the chart page →

12,141
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.13

Open the chart page →

12,141
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.13

Open the chart page →

12,562
backendmojaloop0.1.05 of 6See more

backend mojaloop 0.1.0

5 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.25.13
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
stdlib@go1.17
1.25.13
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
stdlib@go1.23.8
1.25.13
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
stdlib@go1.16.4
1.25.13
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.25.13

Open the chart page →

16,662
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.13

Open the chart page →

19,798
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.25.13

Open the chart page →

6,342
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.3c4a11ae9a1cb
stdlib@go1.25.7
1.25.13

Open the chart page →

2,582
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
stdlib@go1.26.2
1.25.13

Open the chart page →

470
gar-credential-providermondu-aiVerified publisher0.2.11 of 1See more

gar-credential-provider mondu-ai 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.25.13

Open the chart page →

737
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
stdlib@go1.25.9
1.25.13

Open the chart page →

5,381
enterprise-operatormongodb-helm-charts1.33.01 of 1See more

enterprise-operator mongodb-helm-charts 1.33.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
stdlib@go1.24.2
1.25.13

Open the chart page →

1,633
mongodb-query-exportermongodb-query-exporterVerified publisher5.1.01 of 1See more

mongodb-query-exporter mongodb-query-exporter 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
stdlib@go1.20.5
1.25.13

Open the chart page →

981
mongodb-secure-backupmongodb-secure-backup1.0.01 of 2See more

mongodb-secure-backup mongodb-secure-backup 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
stdlib@go1.22.10
1.25.13

Open the chart page →

1,034

Container images carrying it

5,361 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.