StackRadar

CVE-2026-56860

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,638
of 17,828 indexed, latest versions
Container images
5,364
deployed by those charts
Fix available
1 of 2
affected packages

Avoid quadratic complexity in resolvePath in net/url

Carried by container images the latest versions of 4,638 of 17,828 indexed charts deploy, on 5,364 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,364
OSV records
DEBIAN-CVE-2026-56860GO-2026-6218
Also known as
BIT-golang-2026-56860

Charts affected

4,638 by stars
ChartLatestAffected imagesRadar Score
prometheus-couchdb-exportergkarthiks0.1.31 of 1See more

prometheus-couchdb-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
gesellix/couchdb-prometheus-exporter:v27.2.05b891f1fc2b9
stdlib@go1.13.10
1.25.13

Open the chart page →

1,285
glassflow-etlglassflowVerified publisher0.5.2110 of 16See more

glassflow-etl glassflow 0.5.21

10 of the 16 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.25.13
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.25.13
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.13
natsio/nats-server-config-reloader:0.21.110ff229eaf52
stdlib@go1.25.5
1.25.13
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.25.13
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
stdlib@go1.23.0
1.25.13
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
stdlib@go1.25.0
1.25.13
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
stdlib@go1.25.0
1.25.13
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
stdlib@go1.25.4
1.25.13
ghcr.io/glassflow/kafka-kerberos-gateway:latest2ae01c524a6e
stdlib@go1.21.13
1.25.13

Open the chart page →

12,107
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
stdlib@go1.22.10
1.25.13

Open the chart page →

3,330
postgresqlglassflowVerified publisher0.1.91 of 1See more

postgresql glassflow 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.13

Open the chart page →

494
glassflow-operatorglassflow-operatorVerified publisher0.8.51 of 3See more

glassflow-operator glassflow-operator 0.8.5

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
stdlib@go1.25.0
1.25.13

Open the chart page →

773
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
stdlib@go1.24.5
1.25.13

Open the chart page →

2,652
glidergliderVerified publisher0.1.51 of 1See more

glider glider 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
nadoo/glider:0.1638aadefbd607
stdlib@go1.20.14
1.25.13

Open the chart page →

895
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
stdlib@go1.24.6
1.25.13

Open the chart page →

12,550
gnp-stackgnp-stack0.0.57 of 14See more

gnp-stack gnp-stack 0.0.5

7 of the 14 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
stdlib@go1.25.3
1.25.13
rancher/local-path-provisioner:v0.0.329289da488b07
stdlib@go1.24.4
1.25.13
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
stdlib@go1.24.12
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.85.0890b3bb05cf4
stdlib@go1.24.6
1.25.13
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
stdlib@go1.23.7
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.33d671cf20a35
stdlib@go1.25.1
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.13

Open the chart page →

7,727
go-app-helmgo-app-helm0.1.01 of 1See more

go-app-helm go-app-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
manojchaulagain/go-k8s:0.1.0f237b5f637ae
stdlib@go1.20.1
1.25.13

Open the chart page →

1,595
go-file-servergo-file-server1.0.01 of 2See more

go-file-server go-file-server 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
goccx/go-file-server:latestf4b3ebea0303
stdlib@go1.21.10
1.25.13

Open the chart page →

2,223
gofitgofit0.0.11 of 1See more

gofit gofit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/bamaas/gofit:0.0.132b6a174b419
stdlib@go1.22.11
1.25.13

Open the chart page →

651
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.13

Open the chart page →

1,268
gorsegorse-io0.4.23 of 4See more

gorse gorse-io 0.4.2

3 of the 4 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
stdlib@go1.20.1
1.25.13
zhenghaoz/gorse-server:0.4.1239c565685b01
stdlib@go1.20.1
1.25.13
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
stdlib@go1.20.1
1.25.13

Open the chart page →

4,440
gosmee-clientgosmee-clientVerified publisher0.1.31 of 1See more

gosmee-client gosmee-client 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/chmouel/gosmee:v0.32.060b8db1f68cc
stdlib@go1.26.5
1.25.13

Open the chart page →

277
gotwaygotwayVerified publisher0.8.01 of 1See more

gotway gotway 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
stdlib@go1.18.3
1.25.13

Open the chart page →

1,828
Governify-Bluejaygovernify0.1.02 of 12See more

Governify-Bluejay governify 0.1.0

2 of the 12 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
stdlib@go1.17
1.25.13
library/mongo:latest5211c51171f5
stdlib@go1.26.5
1.25.13

Open the chart page →

22,760
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
stdlib@go1.17
1.25.13
library/mongo:latest5211c51171f5
stdlib@go1.26.5
1.25.13

Open the chart page →

24,547
goweeklygoweekly2.0.01 of 1See more

goweekly goweekly 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
stdlib@go1.17.12
1.25.13

Open the chart page →

1,230
harborgpg-dev1.18.35 of 8See more

harbor gpg-dev 1.18.3

5 of the 8 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.14.3a30e5a8be3d9
stdlib@go1.24.13
1.25.13
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
stdlib@go1.24.13
1.25.13
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
stdlib@go1.24.13
1.25.13
goharbor/registry-photon:v2.14.36533fc396cbc
stdlib@go1.24.13
1.25.13
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
stdlib@go1.25.7
1.25.13

Open the chart page →

3,460
ingress-nginxgpg-dev4.9.02 of 2See more

ingress-nginx gpg-dev 4.9.0

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
stdlib@go1.21.5
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.13

Open the chart page →

2,316
jaegergpg-dev3.3.34 of 5See more

jaeger gpg-dev 3.3.3

4 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
stdlib@go1.21.5
1.25.13
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.13
jaegertracing/jaeger-collector:1.53.07f1269222903
stdlib@go1.21.5
1.25.13
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
stdlib@go1.21.5
1.25.13

Open the chart page →

19,460
kube-prometheus-stackgpg-dev84.0.05 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

5 of the 6 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/grafana:13.0.10f86bada30d6
stdlib@go1.26.0
1.25.13
ghcr.io/jkroepke/kube-webhook-certgen:1.8.14f6da0256b1b
stdlib@go1.26.2
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
stdlib@go1.25.8
1.25.13
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.13

Open the chart page →

4,334
kubernetes-dashboardgpg-dev7.5.04 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

4 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.7.060595892c2cf
stdlib@go1.22.3
1.25.13
kubernetesui/dashboard-auth:1.1.307135c09e9ff
stdlib@go1.22.2
1.25.13
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
stdlib@go1.22.1
1.25.13
kubernetesui/dashboard-web:1.4.04445b31a2c25
stdlib@go1.22.3
1.25.13

Open the chart page →

6,139
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
stdlib@go1.21.8
1.25.13

Open the chart page →

1,086
opentelemetry-demogpg-dev0.33.88 of 27See more

opentelemetry-demo gpg-dev 0.33.8

8 of the 27 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
stdlib@go1.23.1
1.25.13
jaegertracing/all-in-one:1.53.060e65bfffe1f
stdlib@go1.21.5
1.25.13
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
stdlib@go1.23.3
1.25.13
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
stdlib@go1.22.5
1.25.13
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
stdlib@go1.22.8
1.25.13
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
stdlib@go1.22.8
1.25.13
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
stdlib@go1.21.5
1.25.13
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
stdlib@go1.23.3
1.25.13

Open the chart page →

50,116
prometheusgpg-dev29.2.16 of 6See more

prometheus gpg-dev 29.2.1

6 of the 6 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1693faa0b8724
stdlib@go1.25.8
1.25.13
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
stdlib@go1.26.2
1.25.13
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.13
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
stdlib@go1.26.2
1.25.13
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
stdlib@go1.25.3
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.13

Open the chart page →

3,309
prometheus-operator-admission-webhookgpg-dev0.18.12 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/admission-webhook:v0.79.2d4c97a1b2d67
stdlib@go1.23.4
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.13

Open the chart page →

1,687
thanosgpg-dev0.5.31 of 1See more

thanos gpg-dev 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
stdlib@go1.25.7
1.25.13

Open the chart page →

602
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
stdlib@go1.25.8
1.25.13

Open the chart page →

1,309
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
stdlib@go1.25.7
1.25.13

Open the chart page →

1,582
whoami-demogpg-dev0.1.01 of 1See more

whoami-demo gpg-dev 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.25.13

Open the chart page →

1,280
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
prom/graphite-exporter:latestc1a266f63a84
stdlib@go1.26.5
1.25.13

Open the chart page →

6,142
cloudcost-exportergrafana1.1.131 of 1See more

cloudcost-exporter grafana 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/cloudcost-exporter:v1.12.0eeb2cfecb23e
stdlib@go1.26.4
1.25.13

Open the chart page →

162
grafana-cloud-onboardinggrafana0.4.75 of 5See more

grafana-cloud-onboarding grafana 0.4.7

5 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/beyla-k8s-cache:253b2f561cb1b
stdlib@go1.25.3
1.25.13
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
stdlib@go1.25.8
1.25.13
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
stdlib@go1.23.6
1.25.13
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.13

Open the chart page →

4,737
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
stdlib@go1.24.6
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.13

Open the chart page →

3,435
k8s-injection-controllergrafana0.2.11 of 1See more

k8s-injection-controller grafana 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/grafana/k8s-injection-controller:0.2.0c5bad40655a3
stdlib@go1.26.5
1.25.13

Open the chart page →

138
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
stdlib@go1.17.8
1.25.13
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
stdlib@go1.15.7
1.25.13
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
stdlib@go1.15.7
1.25.13

Open the chart page →

17,824
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
stdlib@go1.24.6
1.25.13
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
stdlib@go1.24.5
1.25.13
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
stdlib@go1.23.6
1.25.13
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
stdlib@go1.23.7
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.13

Open the chart page →

8,531
snyk-exportergrafana0.1.01 of 1See more

snyk-exporter grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/snyk_exporter:v1.4.1d3c9093401ca
stdlib@go1.21.0
1.25.13

Open the chart page →

670
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
stdlib@go1.23.3
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
stdlib@go1.23.3
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.13
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.25.13

Open the chart page →

5,327
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
stdlib@go1.13.10
1.25.13

Open the chart page →

7,518
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
stdlib@go1.18.10
1.25.13

Open the chart page →

82,839
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/mongo:85d7043a4ffe0
stdlib@go1.26.5
1.25.13

Open the chart page →

5,083
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
stdlib@go1.21.10
1.25.13

Open the chart page →

1,399
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
stdlib@go1.15.2
1.25.13

Open the chart page →

14,305
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
stdlib@go1.22.7
1.25.13

Open the chart page →

2,609
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
stdlib@go1.17.13
1.25.13

Open the chart page →

2,183
routergroundcover1.12.3784 of 7See more

router groundcover 1.12.378

4 of the 7 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
stdlib@go1.26.3
1.25.13
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
stdlib@go1.25.7
1.25.13
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.13
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.13

Open the chart page →

6,256
temporalgroundcover1.12.3781 of 2See more

temporal groundcover 1.12.378

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
stdlib@go1.26.5
1.25.13

Open the chart page →

1,219

Container images carrying it

5,364 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
stdlib@go1.14.10
1.25.13
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
stdlib@go1.21.4
1.25.13
1
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
stdlib@go1.26.5
1.25.13
1
quay.io/nmstate/kubernetes-nmstate-operator:v0.87.04dce694f01ea
stdlib@go1.26.0
1.25.13
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
stdlib@go1.26.1
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.15.310a1165743a1
stdlib@go1.26.4
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
stdlib@go1.25.4
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.14.368336da945bd
stdlib@go1.25.7
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
stdlib@go1.14.4
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
stdlib@go1.22.8
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
stdlib@go1.16
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
stdlib@go1.17.5
1.25.13
1
quay.io/ohiosupercomputercenter/job-pod-reaper:v0.14.0775449888968
stdlib@go1.26.4
1.25.13
1
quay.io/ohiosupercomputercenter/k8-ldap-configmap:v0.16.040d0b67afd77
stdlib@go1.26.4
1.25.13
1
quay.io/ohiosupercomputercenter/k8-namespace-reaper:v0.11.0ead1f817e8c2
stdlib@go1.26.4
1.25.13
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
stdlib@go1.20.10
1.25.13
1
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
stdlib@go1.22.4
1.25.13
1
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
stdlib@go1.24.13
1.25.13
1
quay.io/open-cluster-management/dynamic-scoring-controller:latest587f5bc8f2ed
stdlib@go1.24.13
1.25.13
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
stdlib@go1.24.6
1.25.13
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
stdlib@go1.26.4
1.25.13
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
stdlib@go1.19.13
1.25.13
1
quay.io/openshift/origin-cli:4.66722d5041b47
stdlib@go1.15.14
1.25.13
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
stdlib@go1.16.9
1.25.13
1
quay.io/openshift/origin-csi-external-attacher:latest4f9b3d0f2c7f
stdlib@go1.26.5
1.25.13
1
quay.io/openshift/origin-csi-external-provisioner:lateste4074ec254f5
stdlib@go1.26.5
1.25.13
1
quay.io/openshift/origin-csi-node-driver-registrar:latestea08b5e5f4ab
stdlib@go1.26.5
1.25.13
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
stdlib@go1.21.3
1.25.13
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
stdlib@go1.25.3
1.25.13
1
quay.io/operator-framework/olm1b6002156f56
stdlib@go1.21.7
1.25.13
1
quay.io/operator-framework/olm40d0363f4aa6
stdlib@go1.22.3
1.25.13
1
quay.io/operator-framework/olm:v0.46.04404599eb7b7
stdlib@go1.26.3
1.25.13
1
quay.io/operator-framework/olmf9ea8cef95ac
stdlib@go1.19.6
1.25.13
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
stdlib@go1.25.3
1.25.13
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
stdlib@go1.17.2
1.25.13
1
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
stdlib@go1.16.15
1.25.13
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
stdlib@go1.20.3
1.25.13
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
stdlib@go1.19.1
1.25.13
1
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
stdlib@go1.24.11
1.25.13
1
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
stdlib@go1.25.5
1.25.13
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
stdlib@go1.22.2
1.25.13
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
stdlib@go1.13.1
1.25.13
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
stdlib@go1.14.6
1.25.13
1
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.25.13
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
stdlib@go1.26.2
1.25.13
1
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
stdlib@go1.25.9
1.25.13
1
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
stdlib@go1.17.10
1.25.13
1
quay.io/opstree/loki:3.6-debian13bdfee214c7ea
stdlib@go1.26.2
1.25.13
1
quay.io/opstree/memcached-exporter:0.15.5-debian13cf8f8410eaad
stdlib@go1.26.2
1.25.13
1
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
stdlib@go1.17.8
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.