StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,497
of 17,803 indexed, latest versions
Container images
5,243
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,497 of 17,803 indexed charts deploy, on 5,243 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,243
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,497 by stars
ChartLatestAffected imagesRadar Score
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
stdlib@go1.21.8
1.25.13

Open the chart page →

1,630
syncthingbrandan-schmitz-helm-chartsVerified publisher2.1.01 of 1See more

syncthing brandan-schmitz-helm-charts 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
stdlib@go1.26.3
1.25.13

Open the chart page →

1,224
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
stdlib@go1.13.10
1.25.13

Open the chart page →

7,842
btrfs-nfs-csibtrfs-nfs-csi0.4.06 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

6 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
stdlib@go1.25.7
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
stdlib@go1.25.7
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
stdlib@go1.25.7
1.25.13

Open the chart page →

3,249
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
stdlib@go1.21.4
1.25.13

Open the chart page →

2,049
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
stdlib@go1.14.7
1.25.13

Open the chart page →

2,671
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
stdlib@go1.25.1
1.25.13

Open the chart page →

1,551
buildkit-fleetbuildkit-fleetVerified publisher0.1.21 of 1See more

buildkit-fleet buildkit-fleet 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.0-rootless80b15f0735e8
stdlib@go1.25.7
1.25.13

Open the chart page →

903
nacosbytectl0.1.61 of 1See more

nacos bytectl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.25.13

Open the chart page →

1,888
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
stdlib@go1.24.2
1.25.13

Open the chart page →

1,658
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
stdlib@go1.24.2
1.25.13

Open the chart page →

1,658
pgcagriekinVerified publisher2.1.01 of 2See more

pg cagriekin 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.13

Open the chart page →

2,426
pgvectorcagriekinVerified publisher2.1.02 of 3See more

pgvector cagriekin 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.13
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.25.13

Open the chart page →

4,210
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
stdlib@go1.25.9
1.25.13

Open the chart page →

521
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
stdlib@go1.22.2
1.25.13

Open the chart page →

913
capsulecapsuleOfficialVerified publisher0.14.62 of 2See more

capsule capsule 0.14.6

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.13
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
stdlib@go1.26.4
1.25.13

Open the chart page →

1,239
capsule-proxycapsule-proxyOfficialVerified publisher0.14.12 of 2See more

capsule-proxy capsule-proxy 0.14.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.13
ghcr.io/projectcapsule/capsule-proxy:v0.14.17c90292e3172
stdlib@go1.26.4
1.25.13

Open the chart page →

1,227
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
stdlib@go1.16.2
1.25.13

Open the chart page →

3,512
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
stdlib@go1.23.0
1.25.13

Open the chart page →

1,817
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
stdlib@go1.26.2
1.25.13

Open the chart page →

276
cert-manager-google-cas-issuercert-managerOfficialVerified publisher0.12.01 of 1See more

cert-manager-google-cas-issuer cert-manager 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-google-cas-issuer:v0.12.08bd9cdb714a6
stdlib@go1.26.4
1.25.13

Open the chart page →

164
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
stdlib@go1.22.4
1.25.13
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
stdlib@go1.21.12
1.25.13
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
stdlib@go1.21.12
1.25.13
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
stdlib@go1.21.12
1.25.13
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
stdlib@go1.21.12
1.25.13
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
stdlib@go1.21.12
1.25.13
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
stdlib@go1.21.12
1.25.13

Open the chart page →

12,804
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
stdlib@go1.24.4
1.25.13

Open the chart page →

1,082
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
stdlib@go1.22.0
1.25.13

Open the chart page →

1,039
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
stdlib@go1.23.7
1.25.13
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.25.13
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.25.13
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

16,224
chatclichatcliVerified publisher1.205.11 of 2See more

chatcli chatcli 1.205.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
stdlib@go1.23.10
1.25.13

Open the chart page →

1,028
etcd-defragchristianhuthVerified publisher1.6.11 of 1See more

etcd-defrag christianhuth 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.7.13c66a5191d37
stdlib@go1.26.5
1.25.13

Open the chart page →

143
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.13
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
stdlib@go1.24.6
1.25.13
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.25.13

Open the chart page →

11,031
shlink-backendchristianhuthVerified publisher11.11.11 of 1See more

shlink-backend christianhuth 11.11.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
shlinkio/shlink:5.1.6666cc24edf72
stdlib@go1.26.4
1.25.13

Open the chart page →

322
squestchristianhuthVerified publisher6.6.82 of 4See more

squest christianhuth 6.6.8

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.13
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13

Open the chart page →

10,173
typo3christianhuthVerified publisher7.7.11 of 2See more

typo3 christianhuth 7.7.1

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.13

Open the chart page →

8,689
challengerchronicleVerified publisher0.1.11 of 1See more

challenger chronicle 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.25.13

Open the chart page →

978
erpcchronicleVerified publisher0.7.01 of 1See more

erpc chronicle 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
stdlib@go1.26.4
1.25.13

Open the chart page →

391
spectrechronicleVerified publisher0.3.81 of 1See more

spectre chronicle 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
stdlib@go1.25.5
1.25.13

Open the chart page →

1,548
validatorchronicleVerified publisher0.8.01 of 1See more

validator chronicle 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/ghost:0.78.5951d71162065
stdlib@go1.26.5
1.25.13

Open the chart page →

507
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
stdlib@go1.22.1
1.25.13

Open the chart page →

643
clamav-restclamav-rest-apiVerified publisher0.1.01 of 1See more

clamav-rest clamav-rest-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.25.13

Open the chart page →

515
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.13

Open the chart page →

2,360
clickhouse-operator-helmclickhouse-operator0.0.71 of 1See more

clickhouse-operator-helm clickhouse-operator 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/clickhouse/clickhouse-operator:v0.0.7d51ca53f0967
stdlib@go1.26.5
1.25.13

Open the chart page →

118
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
stdlib@go1.20.1
1.25.13
cloudbees/sidecar-injector:2.3.38f102ef0383a
stdlib@go1.20.1
1.25.13

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.13
prom/prometheus:v2.21.0d43417c260e5
stdlib@go1.15.2
1.25.13

Open the chart page →

4,265
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
stdlib@go1.17.6
1.25.13
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
stdlib@go1.18.6
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
stdlib@go1.17.6
1.25.13

Open the chart page →

7,598
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.25.13

Open the chart page →

2,714
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.25.13

Open the chart page →

1,724
grafanacloudposse0.2.61 of 1See more

grafana cloudposse 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.26.5
1.25.13

Open the chart page →

745
openstack-manila-csicloud-provider-openstack2.36.35 of 5See more

openstack-manila-csi cloud-provider-openstack 2.36.3

5 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
stdlib@go1.26.2
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
stdlib@go1.24.6
1.25.13

Open the chart page →

3,785
cloudttycloudtty0.8.102 of 2See more

cloudtty cloudtty 0.8.10

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.1023e8d178e02c
stdlib@go1.25.2
1.25.13
ghcr.io/cloudtty/cloudshell-operator:v0.8.1014f036e33ef1
stdlib@go1.21.11
1.25.13

Open the chart page →

3,026
cluster-api-provider-oxidecluster-api-provider-oxide0.2.31 of 1See more

cluster-api-provider-oxide cluster-api-provider-oxide 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/oxidecomputer/cluster-api-provider-oxide:0.2.37b05d3bbfbfa
stdlib@go1.26.4
1.25.13

Open the chart page →

129
cluster-api-visualizercluster-api-visualizer1.5.01 of 1See more

cluster-api-visualizer cluster-api-visualizer 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
stdlib@go1.24.11
1.25.13

Open the chart page →

558
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.13

Open the chart page →

5,062

Container images carrying it

5,243 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
otel/opentelemetry-collector-contrib:0.157.0f2f01157055a
stdlib@go1.26.5
1.25.13
1
otel/opentelemetry-collector-contrib:0.139.0faf125d656fa
stdlib@go1.25.3
1.25.13
1
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
stdlib@go1.24.0
1.25.13
1
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
stdlib@go1.20
1.25.13
1
outcoldsolutions/collectorforopenshift:26.04.45000a5f27bbb
stdlib@go1.26.4
1.25.13
1
outlinewiki/outline:0.82.0494dfb9249a6
stdlib@go1.20.12
1.25.13
1
ovhplatform/what-is-my-pod:1.0.16d4d455e9aba
stdlib@go1.16.14
1.25.13
1
owncloud/ocis:7.1.388e7c854517d
stdlib@go1.22.12
1.25.13
1
owncloud/ocis:8.0.1b38fd8fdd58f
stdlib@go1.25.7
1.25.13
1
owncloud/ocis:1.7.0d2efcae92c84
stdlib@go1.16.5
1.25.13
1
owncloud/server:10.15.051d9b74fc2a8
stdlib@go1.22.4
1.25.13
1
owncloud/server:10.16.274c53d341076
stdlib@go1.26.3
1.25.13
1
owncloud/server:10.16.3b3f9efdcd7f7
stdlib@go1.26.5
1.25.13
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
stdlib@go1.17
1.25.13
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.25.13
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.25.13
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.25.13
1
pannoi/kollektor:1.0.59559617788fc
stdlib@go1.20.14
1.25.13
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.25.13
1
penpotapp/backend:2.17.2770b55f6e51b
stdlib@go1.26.5
1.25.13
1
penpotapp/exporter:2.17.272a8061e8806
stdlib@go1.26.5
1.25.13
1
penpotapp/mcp:2.17.284f3f07ead11
stdlib@go1.26.5
1.25.13
1
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.25.13
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
stdlib@go1.25.4
1.25.13
1
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
stdlib@go1.24.3
1.25.13
1
percona/percona-server-mongodb-operator:1.23.0feaff989e253
stdlib@go1.26.5
1.25.13
1
percona/percona-server-mysql-operator:1.2.028bfc38c1d4b
stdlib@go1.26.4
1.25.13
1
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
stdlib@go1.19.9
1.25.13
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
stdlib@go1.21.7
1.25.13
1
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
stdlib@go1.26.4
1.25.13
1
percona/pmm-server:3.9.1003f9c25f842
stdlib@go1.26.4
1.25.13
1
persesdev/perses:v0.54.0a0e34ddaf9d7
stdlib@go1.26.5
1.25.13
1
persesdev/perses-operator:v0.5.08f8d7b09caef
stdlib@go1.26.5
1.25.13
1
peterdavehello/tor-socks-proxy:latest0cc12d36d312
stdlib@go1.26.2
1.25.13
1
pgsharding/spqr-router:nightly-2.8.3-1839-f66048d84734940216d3
stdlib@go1.25.4
1.25.13
1
pgvector/pgvector:pg17cf134a767f47
stdlib@go1.24.6
1.25.13
1
philmtd/full-house:1.9.0d68a6bb8a2bf
stdlib@go1.26.3
1.25.13
1
phntom/chadbot:0.2.397c28e4178ad
stdlib@go1.21.5
1.25.13
1
phntom/chartmuseum:v0.16.053883b65d9b7
stdlib@go1.19.3
1.25.13
1
phntom/chartmuseum:v0.15.29242b4df9e65
stdlib@go1.18.5
1.25.13
1
phntom/codimd:2.4.31b9aafbb62e6
stdlib@go1.16
1.25.13
1
phntom/external-dns-host-network:0.0.123adadbac8443
stdlib@go1.19.2
1.25.13
1
phntom/goalert:0.0.298ca4df55499b
stdlib@go1.21.5
1.25.13
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
stdlib@go1.20.7
1.25.13
1
phntom/mindav:0.1.7-kix35695f546abbb
stdlib@go1.16.2
1.25.13
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
stdlib@go1.19.2
1.25.13
1
photoprism/photoprism:231128-ce284de9cc4f9c
stdlib@go1.21.4
1.25.13
1
photoprism/photoprism:220629-jammy2954334adbda
stdlib@go1.18.3
1.25.13
1
photoprism/photoprism:260601650c6ad5a651
stdlib@go1.26.3
1.25.13
1
photoprism/photoprism:260728958642220223
stdlib@go1.26.5
1.25.13
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.