StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,676
of 17,985 indexed, latest versions
Container images
5,331
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,676 of 17,985 indexed charts deploy, on 5,331 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+195 more1.25.135,331
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,676 by stars
ChartLatestAffected imagesRadar Score
matrixzekker6Verified publisher3.32.01 of 4See more

matrix zekker6 3.32.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.162.06b84a7bbac36
stdlib@go1.24.4
1.25.13

Open the chart page →

5,739
eshoponabpabp-charts1.0.02 of 15See more

eshoponabp abp-charts 1.0.0

2 of the 15 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.25.13
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.13

Open the chart page →

19,779
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
stdlib@go1.18.2
1.25.13

Open the chart page →

3,764
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/angelnu/gateway-admision-controller:v3.12.06f6ab596afd5
stdlib@go1.24.2
1.25.13

Open the chart page →

1,403
ansible-semaphoreansible-semaphore0.1.01 of 1See more

ansible-semaphore ansible-semaphore 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.25.13

Open the chart page →

4,032
aperture-controlleraperture2.34.03 of 5See more

aperture-controller aperture 2.34.0

3 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
stdlib@go1.21.5
1.25.13
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
quay.io/prometheus/prometheus:v2.33.591100b06e86d
stdlib@go1.17.8
1.25.13

Open the chart page →

4,684
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
stdlib@go1.18
1.25.13

Open the chart page →

3,313
limesurveyarea-42Verified publisher0.3.991See more

limesurvey area-42 0.3.99

1 container image this version deploys carries CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.13

Open the chart page →

—
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
stdlib@go1.16.9
1.25.13

Open the chart page →

9,166
prometheusaveshaVerified publisher19.3.04 of 4See more

prometheus avesha 19.3.0

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.13
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.13
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
stdlib@go1.19.3
1.25.13

Open the chart page →

5,495
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
stdlib@go1.15.2
1.25.13

Open the chart page →

2,246
aws-node-termination-handleraws-node-termination-handler0.27.61 of 1See more

aws-node-termination-handler aws-node-termination-handler 0.27.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.25.69ad31fb4e5be
stdlib@go1.25.8
1.25.13

Open the chart page →

524
snapschedulerbackube-helm-chartsVerified publisher3.5.02 of 2See more

snapscheduler backube-helm-charts 3.5.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/backube/snapscheduler:3.5.035ac95c51780
stdlib@go1.24.3
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.13

Open the chart page →

1,252
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
stdlib@go1.20.7
1.25.13

Open the chart page →

1,919
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
stdlib@go1.19.13
1.25.13

Open the chart page →

1,156
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
stdlib@go1.25.1
1.25.13

Open the chart page →

1,704
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.25.13

Open the chart page →

70,547
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
stdlib@go1.21.4
1.25.13

Open the chart page →

1,929
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
stdlib@go1.19.9
1.25.13

Open the chart page →

1,693
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
stdlib@go1.26.5
1.25.13

Open the chart page →

13,634
version-checkercert-managerVerified publisher0.11.01 of 1See more

version-checker cert-manager 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.11.0eae9a374d22f
stdlib@go1.26.4
1.25.13

Open the chart page →

275
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
stdlib@go1.17.11
1.25.13
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
stdlib@go1.17.11
1.25.13
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
stdlib@go1.17.11
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
stdlib@go1.17.11
1.25.13

Open the chart page →

7,805
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
stdlib@go1.23.5
1.25.13

Open the chart page →

1,456
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.25.13

Open the chart page →

1,822
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
stdlib@go1.22.3
1.25.13

Open the chart page →

796
ghostcloudpirates-ghostVerified publisher0.20.263 of 3See more

ghost cloudpirates-ghost 0.20.26

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/ghost:6.64.0586821cfebac
stdlib@go1.24.6
1.25.13
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.25.13
library/mariadb:13.0.2d4fdec0510ad
stdlib@go1.24.6
1.25.13

Open the chart page →

7,901
openstack-manila-csicloud-provider-openstack2.36.35 of 5See more

openstack-manila-csi cloud-provider-openstack 2.36.3

5 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
stdlib@go1.26.2
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
stdlib@go1.24.6
1.25.13

Open the chart page →

3,862
dumpscriptcloudscriptVerified publisher1.10.01 of 1See more

dumpscript cloudscript 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.44-alpine-edgeac7c4c5d4d07
stdlib@go1.26.5
1.25.13

Open the chart page →

218
clowardenclowarden0.2.32 of 4See more

clowarden clowarden 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.25.13
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
stdlib@go1.25.3
1.25.13

Open the chart page →

6,007
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
stdlib@go1.24.5
1.25.13

Open the chart page →

757
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
stdlib@go1.18
1.25.13

Open the chart page →

1,703
coder-observabilitycoder-observabilityVerified publisher0.7.314 of 21See more

coder-observability coder-observability 0.7.3

14 of the 21 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
stdlib@go1.22.1
1.25.13
grafana/grafana:10.4.19a9043254ba16
stdlib@go1.24.3
1.25.13
grafana/loki:3.1.0d947e68a84d9
stdlib@go1.22.2
1.25.13
grafana/loki-canary:3.1.039baf6d67f85
stdlib@go1.22.2
1.25.13
prom/memcached-exporter:v0.14.2d8a61419b841
stdlib@go1.21.5
1.25.13
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.13
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
stdlib@go1.18.6
1.25.13
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
stdlib@go1.18.6
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.13
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.25.13
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
stdlib@go1.22.5
1.25.13
quay.io/prometheuscommunity/postgres-exporter:latestac5ec343104f
stdlib@go1.26.4
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.13

Open the chart page →

25,337
convertigoconvertigoOfficialVerified publisher8.4.52 of 5See more

convertigo convertigo 8.4.5

2 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
stdlib@go1.21.5
1.25.13
timescale/timescaledb:latest-pg166f139d560429
stdlib@go1.26.2
1.25.13

Open the chart page →

16,348
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
stdlib@go1.16.6
1.25.13

Open the chart page →

3,135
cosmocosmo-platformOfficialVerified publisher0.20.06 of 10See more

cosmo cosmo-platform 0.20.0

6 of the 10 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
stdlib@go1.24.6
1.25.13
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.25.13
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stdlib@go1.22.3
1.25.13
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
stdlib@go1.23.6
1.25.13
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
stdlib@go1.23.6
1.25.13
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.25.13

Open the chart page →

31,714
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.13

Open the chart page →

1,640
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
stdlib@go1.21.13
1.25.13

Open the chart page →

1,316
deepflowdeepflow6.2.2015 of 8See more

deepflow deepflow 6.2.201

5 of the 8 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.25.13
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
stdlib@go1.19.3
1.25.13
deepflowce/deepflow-server:v6.2.21477e7334d13
stdlib@go1.18.10
1.25.13
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.25.13
grafana/grafana:9.3.6e5a9655dabef
stdlib@go1.19.4
1.25.13

Open the chart page →

16,330
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
stdlib@go1.21.10
1.25.13

Open the chart page →

3,698
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
stdlib@go1.21.7
1.25.13

Open the chart page →

1,646
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
stdlib@go1.17.6
1.25.13

Open the chart page →

2,544
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.25.13

Open the chart page →

1,280
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.13

Open the chart page →

4,580
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
stdlib@go1.24.9
1.25.13

Open the chart page →

2,154
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.25.13

Open the chart page →

2,268
postgres-pgdump-backupeugen0.7.61 of 1See more

postgres-pgdump-backup eugen 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.13

Open the chart page →

356
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.13

Open the chart page →

12,258
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.13

Open the chart page →

14,908
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.13

Open the chart page →

14,141
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.13

Open the chart page →

5,492

Container images carrying it

5,331 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56859.

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.