StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,497
of 17,803 indexed, latest versions
Container images
5,243
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,497 of 17,803 indexed charts deploy, on 5,243 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,243
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,497 by stars
ChartLatestAffected imagesRadar Score
serviceexampleservice-example-helm-chart0.1.01 of 4See more

serviceexample service-example-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.26.5
1.25.13

Open the chart page →

2,332
service-exampleservice-example-jt0.1.15 of 9See more

service-example service-example-jt 0.1.1

5 of the 9 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnami/mongodb:latest11ece5ac9685
stdlib@go1.26.5
1.25.13
library/nats:2.12.2-alpine2d5fce3229ae
stdlib@go1.25.4
1.25.13
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.13
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.25.13
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.25.13

Open the chart page →

7,584
ccx-monitoringseveralnines0.6.215 of 7See more

ccx-monitoring severalnines 0.6.21

5 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
stdlib@go1.25.5
1.25.13
victoriametrics/victoria-metrics:v1.120.0a1cb2f3dfd45
stdlib@go1.24.4
1.25.13
victoriametrics/vmalert:v1.96.0150cd08fde94
stdlib@go1.21.5
1.25.13
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
stdlib@go1.20.10
1.25.13

Open the chart page →

7,740
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
stdlib@go1.19.10
1.25.13

Open the chart page →

1,699
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.13

Open the chart page →

3,088
operatorshopware-storeVerified publisher1.8.11 of 1See more

operator shopware-store 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/shopware/shopware-operator:1.8.187db0eda7a03
stdlib@go1.26.0
1.25.13

Open the chart page →

571
shopwareshopware-storeVerified publisher2.1.21 of 5See more

shopware shopware-store 2.1.2

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
stdlib@go1.21.7
1.25.13

Open the chart page →

4,132
bffshortlink0.2.11 of 1See more

bff shortlink 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.13

Open the chart page →

1,698
linkshortlink0.7.31 of 1See more

link shortlink 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.13

Open the chart page →

1,682
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,261
findmydevicesi-gitops0.14.01 of 1See more

findmydevice si-gitops 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.gitlab.com/fmd-foss/fmd-server:0.16.0-distrolessbb57d6982fea
stdlib@go1.26.4
1.25.13

Open the chart page →

74
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
stdlib@go1.24.6
1.25.13

Open the chart page →

2,700
nut-exportersi-gitops0.5.01 of 1See more

nut-exporter si-gitops 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
stdlib@go1.26.3
1.25.13

Open the chart page →

811
backendsignalen4.24.02 of 4See more

backend signalen 4.24.0

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.25.13
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.25.13

Open the chart page →

11,751
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.25.13

Open the chart page →

2,182
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
stdlib@go1.24.6
1.25.13

Open the chart page →

1,686
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.25.13

Open the chart page →

2,923
local-static-provisionersig-storage-local-static-provisioner2.9.01 of 1See more

local-static-provisioner sig-storage-local-static-provisioner 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.13

Open the chart page →

1,280
ctlogsigstoreVerified publisher0.2.683 of 4See more

ctlog sigstore 0.2.68

3 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
stdlib@go1.25.0
1.25.13
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
stdlib@go1.25.0
1.25.13
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
stdlib@go1.25.0
1.25.13

Open the chart page →

2,749
ctlog-tilessigstoreVerified publisher0.1.71 of 1See more

ctlog-tiles sigstore 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/transparency-dev/tesseract/posix:v0.1.2b044edd23888
stdlib@go1.25.8
1.25.13

Open the chart page →

280
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
stdlib@go1.26.0
1.25.13

Open the chart page →

431
trilliansigstoreVerified publisher0.3.204 of 5See more

trillian sigstore 0.3.20

4 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.25.13
ghcr.io/sigstore/scaffolding/createdbdigest-pinned3cee6c78973b
stdlib@go1.25.0
1.25.13
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
stdlib@go1.26.0
1.25.13
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
stdlib@go1.26.0
1.25.13

Open the chart page →

2,757
tsasigstoreVerified publisher2.1.31 of 1See more

tsa sigstore 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sigstore/timestamp-server:v2.1.08637f0482ed1
stdlib@go1.25.1
1.25.13

Open the chart page →

610
tufsigstoreVerified publisher0.1.321 of 1See more

tuf sigstore 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/serverdigest-pinnedae8eb69c7b70
stdlib@go1.25.0
1.25.13

Open the chart page →

768
counter-dhlsikademo0.3.01 of 3See more

counter-dhl sikademo 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ondrejsika/counter:latestd95eaeee2172
stdlib@go1.26.2
1.25.13

Open the chart page →

4,966
test-hello-worldsikademo0.1.01 of 1See more

test-hello-world sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
stdlib@go1.26.2
1.25.13

Open the chart page →

1,215
hello-worldsikalabs0.17.01 of 1See more

hello-world sikalabs 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
stdlib@go1.26.2
1.25.13

Open the chart page →

1,215
hello-world-examplesikalabs0.1.31 of 1See more

hello-world-example sikalabs 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
stdlib@go1.26.2
1.25.13

Open the chart page →

1,215
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
stdlib@go1.19.6
1.25.13

Open the chart page →

2,870
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
stdlib@go1.21.4
1.25.13

Open the chart page →

2,347
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.25.13

Open the chart page →

2,381
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
stdlib@go1.22.3
1.25.13

Open the chart page →

1,162
signpostsikalabs0.5.01 of 1See more

signpost sikalabs 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
sikalabs/signpost:v0.7.0c8b0e21d61b4
stdlib@go1.24.6
1.25.13

Open the chart page →

316
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
stdlib@go1.20.5
1.25.13

Open the chart page →

1,502
headscalesinextraVerified publisher0.1.01 of 1See more

headscale sinextra 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.29.30e7f1c6e4ce6
stdlib@go1.26.5
1.25.13

Open the chart page →

573
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
stdlib@go1.25.12
1.25.13

Open the chart page →

3,085
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
stdlib@go1.18.10
1.25.13

Open the chart page →

2,172
mongosqldsinextraVerified publisher0.3.71 of 1See more

mongosqld sinextra 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
stdlib@go1.23.8
1.25.13

Open the chart page →

2,613
mongosyncsinextraVerified publisher0.4.01 of 1See more

mongosync sinextra 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
stdlib@go1.24.4
1.25.13

Open the chart page →

2,874
pgbouncersinextraVerified publisher0.17.01 of 1See more

pgbouncer sinextra 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
stdlib@go1.24.6
1.25.13

Open the chart page →

1,969
system-upgrade-controllersinextraVerified publisher0.6.11 of 1See more

system-upgrade-controller sinextra 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
rancher/system-upgrade-controller:v0.19.234fa058fe453
stdlib@go1.25.8
1.25.13

Open the chart page →

253
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
stdlib@go1.25.5
1.25.13

Open the chart page →

1,082
talos-backupsinextraVerified publisher0.1.21 of 1See more

talos-backup sinextra 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/siderolabs/talos-backup:v0.1.0-beta.203a71e140f1d
stdlib@go1.23.0
1.25.13

Open the chart page →

905
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
stdlib@go1.21.11
1.25.13

Open the chart page →

2,448
mariadbsitepilot1.0.31 of 1See more

mariadb sitepilot 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
stdlib@go1.24.6
1.25.13

Open the chart page →

2,876
network-observerskupper-network-observerVerified publisher2.2.21 of 3See more

network-observer skupper-network-observer 2.2.2

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.11.3c0b857aead0d
stdlib@go1.26.2
1.25.13

Open the chart page →

618
skyhook-agentskyhookVerified publisher1.3.151 of 1See more

skyhook-agent skyhook 1.3.15

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/skyhook-io/skyhook-connector:v2.3.23deb8e4b1aaa
stdlib@go1.26.0
1.25.13

Open the chart page →

299
skyhook-connectorskyhookVerified publisher1.3.251 of 1See more

skyhook-connector skyhook 1.3.25

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/skyhook-io/skyhook-connector:v2.5.56c4e3336600d
stdlib@go1.26.4
1.25.13

Open the chart page →

132
mimirskyloud-helm-chartsVerified publisher5.5.14 of 5See more

mimir skyloud-helm-charts 5.5.1

4 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/mimir:r292-5f018727476e456c738
stdlib@go1.22.3
1.25.13
grafana/rollout-operator:v0.14.03409edfb45c7
stdlib@go1.22.1
1.25.13
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
stdlib@go1.21.1
1.25.13
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
stdlib@go1.21.1
1.25.13

Open the chart page →

10,819
tailscale-operatorskyloud-helm-chartsVerified publisher1.70.31 of 1See more

tailscale-operator skyloud-helm-charts 1.70.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.70.08edd06cf5bac
stdlib@go1.22.5
1.25.13

Open the chart page →

1,045

Container images carrying it

5,243 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
stdlib@go1.25.12
1.25.13
4
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.13
4
ghcr.io/linuxserver/plex:latest7f9a1d574958
stdlib@go1.26.5
1.25.13
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
stdlib@go1.18.10
1.25.13
4
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
stdlib@go1.25.0
1.25.13
4
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
stdlib@go1.22.4
1.25.13
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.25.13
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.25.13
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.25.13
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.25.13
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.13
4
quay.io/prometheus/mysqld-exporter:latest:v0.20.0abed8dac117b
stdlib@go1.26.5
1.25.13
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.13
4
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
stdlib@go1.23.7
1.25.13
4
quay.io/thanos/thanos:v0.42.4b567818fe608
stdlib@go1.26.5
1.25.13
4
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
stdlib@go1.26.5
1.25.13
4
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
stdlib@go1.26.5
1.25.13
4
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
stdlib@go1.26.5
1.25.13
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.13
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.13
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
stdlib@go1.16.9
1.25.13
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
stdlib@go1.24.4
1.25.13
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
stdlib@go1.24.4
1.25.13
4
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
stdlib@go1.26.4
1.25.13
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
stdlib@go1.22.2
1.25.13
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
stdlib@go1.23.1
1.25.13
4
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
stdlib@go1.23.1
1.25.13
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
stdlib@go1.21.5
1.25.13
4
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
stdlib@go1.24.2
1.25.13
4
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
stdlib@go1.25.7
1.25.13
4
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
stdlib@go1.26.3
1.25.13
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.13
4
alfhou/hammond:v0.0.24c85dc0293aa1
stdlib@go1.20.6
1.25.13
3
alpine/git:latest:v2.54.06f3b5029566d
stdlib@go1.26.3
1.25.13
3
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.12
1.25.13
3
bitnamilegacy/kubectl:latestcd354d5b2556
stdlib@go1.24.5
1.25.13
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.13
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
stdlib@go1.25.0
1.25.13
3
bitnami/mongodb:latest9aa916500f02
stdlib@go1.26.5
1.25.13
3
caddy/ingress:v0.2.118d1366fc0e9
stdlib@go1.21.4
1.25.13
3
ciscolabs/rtsp-server:latestb59fc10bb821
stdlib@go1.19.2
1.25.13
3
cloudflare/cloudflared:2026.8.3:latest51c9cefcb456
stdlib@go1.26.4
1.25.13
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
stdlib@go1.25.7
1.25.13
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
stdlib@go1.23.12
1.25.13
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
stdlib@go1.16
1.25.13
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
stdlib@go1.15
1.25.13
3
derailed/popeye:v0.22.18e68e22c7663
stdlib@go1.23.5
1.25.13
3
dgraph/dgraph:v21.12.03b55ea83fffe
stdlib@go1.17.3
1.25.13
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
stdlib@go1.26.5
1.25.13
3
envoyproxy/gateway:v1.7.5156b7d32c73b
stdlib@go1.26.5
1.25.13
3

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.