StackRadar

CVE-2026-56859

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,497
of 17,803 indexed, latest versions
Container images
5,243
deployed by those charts
Fix available
1 of 2
affected packages

Add recursion depth guard during decode in encoding/xml

Carried by container images the latest versions of 4,497 of 17,803 indexed charts deploy, on 5,243 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,243
OSV records
DEBIAN-CVE-2026-56859GO-2026-6088
Also known as
BIT-golang-2026-56859

Charts affected

4,497 by stars
ChartLatestAffected imagesRadar Score
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
stdlib@go1.17.8
1.25.13

Open the chart page →

1,827
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
stdlib@go1.13.5
1.25.13

Open the chart page →

4,223
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.25.13

Open the chart page →

13,669
steadybit-agentsteadybit3.1.1662 of 6See more

steadybit-agent steadybit 3.1.166

2 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/steadybit/extension-container:v1.8.1ae79f958b479
stdlib@go1.25.12
1.25.13
ghcr.io/steadybit/extension-host:v1.8.103a5ef26aac5
stdlib@go1.25.12
1.25.13

Open the chart page →

4,168
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,261
snapshot-controllerstevehipwellVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.13

Open the chart page →

495
vertical-pod-autoscalerstevehipwellVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
stdlib@go1.26.5
1.25.13

Open the chart page →

228
snapshot-controllerstevehipwell-helm-charts-snapshot-controllerVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell-helm-charts-snapshot-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.13

Open the chart page →

495
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.13

Open the chart page →

1,526
meerkat-crmstone0.3.01 of 1See more

meerkat-crm stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/fbuchner/meerkat-crm:1.7.0d513bdd3ae80
stdlib@go1.26.5
1.25.13

Open the chart page →

104
pulsar-resources-operatorstreamnative0.21.11 of 1See more

pulsar-resources-operator streamnative 0.21.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
streamnative/pulsar-resources-operator:v0.21.11886043c24d0
stdlib@go1.25.12
1.25.13

Open the chart page →

128
sn-platform-slimstreamnative1.11.443 of 6See more

sn-platform-slim streamnative 1.11.44

3 of the 6 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.13
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
stdlib@go1.20.4
1.25.13
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.13

Open the chart page →

62,314
supabase-operatorstrrl-helm2026.7.251 of 1See more

supabase-operator strrl-helm 2026.7.25

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/strrl/supabase-operator:2026.7.2587d083ab8980
stdlib@go1.25.12
1.25.13

Open the chart page →

237
wonder-mesh-netstrrl-helm2026.629.02 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
headscale/headscale:0.27.1cd37b3001857
stdlib@go1.25.1
1.25.13
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
stdlib@go1.25.11
1.25.13

Open the chart page →

5,158
stunner-devstunner1.2.12 of 2See more

stunner-dev stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-gateway-operator-devstunner1.1.12 of 2See more

stunner-gateway-operator-dev stunner 1.1.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-premiumstunner1.2.12 of 2See more

stunner-premium stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
stdlib@go1.26.4
1.25.13
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13

Open the chart page →

267
stunner-prometheusstunner0.2.14 of 4See more

stunner-prometheus stunner 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.26.5
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
stdlib@go1.23.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
stdlib@go1.23.2
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.13

Open the chart page →

3,064
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
stdlib@go1.24.3
1.25.13

Open the chart page →

2,617
orchestratorsubstraVerified publisher8.8.02 of 3See more

orchestrator substra 8.8.0

2 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
stdlib@go1.21.13
1.25.13

Open the chart page →

3,058
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

4,851
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
stdlib@go1.22.5
1.25.13

Open the chart page →

1,596
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
stdlib@go1.15.2
1.25.13

Open the chart page →

2,354
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
stdlib@go1.17.8
1.25.13

Open the chart page →

2,071
stresssudermanjr0.2.01 of 1See more

stress sudermanjr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
stdlib@go1.26.5
1.25.13

Open the chart page →

753
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.13

Open the chart page →

2,130
ingress-nginx-external-lbsuminhong1.0.02 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
stdlib@go1.22.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
stdlib@go1.21.6
1.25.13

Open the chart page →

2,094
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
stdlib@go1.20.7
1.25.13

Open the chart page →

1,801
hello-worldsumudu-repo1.0.01 of 1See more

hello-world sumudu-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
sumuduliya/hello-world:latestb7788a2984a3
stdlib@go1.19.13
1.25.13

Open the chart page →

940
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,261
supabase-operatorsupabse0.1.31 of 1See more

supabase-operator supabse 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/supabase-community/supabase-operator:v0.1.3253a6dcbf4f0
stdlib@go1.25.12
1.25.13

Open the chart page →

237
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
stdlib@go1.17.6
1.25.13

Open the chart page →

2,371
superset-operatorsuperset-kubernetes-operatorVerified publisher0.2.01 of 1See more

superset-operator superset-kubernetes-operator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/apache/superset-kubernetes-operator:0.2.04351831f757f
stdlib@go1.26.5
1.25.13

Open the chart page →

111
do-database-metrics-adaptersupporttools1.0.21 of 1See more

do-database-metrics-adapter supporttools 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
supporttools/do-database-metrics-adapter:1.0.2ab55fd5a69c3
stdlib@go1.22.3
1.25.13

Open the chart page →

430
do-operatorsupporttools0.1.71 of 2See more

do-operator supporttools 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
digitalocean/do-operator:v0.1.65e5deb4db76e
stdlib@go1.18.10
1.25.13

Open the chart page →

1,063
go-redis-proxysupporttools0.0.71 of 1See more

go-redis-proxy supporttools 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
supporttools/go-redis-proxy:0.0.7cbd45f6b02b8
stdlib@go1.21.6
1.25.13

Open the chart page →

529
go-web-cachesupporttools1.3.21 of 1See more

go-web-cache supporttools 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
supporttools/go-web-cache:v1.3.2f4f775dd43b9
stdlib@go1.21.6
1.25.13

Open the chart page →

511
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
stdlib@go1.19.13
1.25.13

Open the chart page →

2,680
powerdns-admin-proxysupporttools0.1.51 of 1See more

powerdns-admin-proxy supporttools 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
supporttools/powerdns-admin-proxy:5e3687d66bcfa
stdlib@go1.21.3
1.25.13

Open the chart page →

558
push-to-k8ssupporttools1.1.21 of 1See more

push-to-k8s supporttools 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
cube8021/push-to-k8s:v1.1.21be9baf096ff
stdlib@go1.22.4
1.25.13

Open the chart page →

530
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
stdlib@go1.24.13
1.25.13

Open the chart page →

3,496
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.13

Open the chart page →

12,739
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
stdlib@go1.20.4
1.25.13

Open the chart page →

10,997
icinga2svtech-public-helm-charts1.0.02 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.13
svtechnmaa/svtech_icingadb:v1.1.26d91c2e4e882
stdlib@go1.21.5
1.25.13

Open the chart page →

5,561
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
stdlib@go1.21.6
1.25.13

Open the chart page →

2,052
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
stdlib@go1.21.3
1.25.13

Open the chart page →

1,480
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.13

Open the chart page →

71,130
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
stdlib@go1.20.5
1.25.13

Open the chart page →

71,563
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
stdlib@go1.21.5
1.25.13

Open the chart page →

2,336
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-56859.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
stdlib@go1.23.9
1.25.13

Open the chart page →

1,369

Container images carrying it

5,243 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.25.13
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
stdlib@go1.25.6
1.25.13
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.25.13
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
stdlib@go1.25.5
1.25.13
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
stdlib@go1.14.15
1.25.13
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
stdlib@go1.19.13
1.25.13
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
stdlib@go1.20.4
1.25.13
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
stdlib@go1.25.0
1.25.13
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
stdlib@go1.25.0
1.25.13
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
stdlib@go1.25.5
1.25.13
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
stdlib@go1.20.7
1.25.13
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
stdlib@go1.25.5
1.25.13
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.25.13
3
quay.io/devtron/nats-box:latest48cdd3054b20
stdlib@go1.19.2
1.25.13
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.25.13
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.25.13
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
stdlib@go1.21.5
1.25.13
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
stdlib@go1.18.10
1.25.13
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.25.13
3
quay.io/jcmoraisjr/haproxy-ingress:v0.16.16fd744191ef6
stdlib@go1.25.9
1.25.13
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.25.13
3
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.25.13
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.25.13
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.13
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.13
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.13
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.13
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
stdlib@go1.16.7
1.25.13
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
stdlib@go1.25.9
1.25.13
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.25.13
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
stdlib@go1.25.8
1.25.13
3
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
stdlib@go1.26.4
1.25.13
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
stdlib@go1.16
1.25.13
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.13
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.13
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.13
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
stdlib@go1.26.0
1.25.13
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
stdlib@go1.17.3
1.25.13
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.13
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.13
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.13
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.25.13
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.25.13
3
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
stdlib@go1.26.5
1.25.13
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.13
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.13
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.13
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
stdlib@go1.24.1
1.25.13
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.25.13
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.13
3

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.