StackRadar

CVE-2026-56864

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
457
of 17,787 indexed, latest versions
Container images
424
deployed by those charts
Fix available
1 of 2
affected packages

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Carried by container images the latest versions of 457 of 17,787 indexed charts deploy, on 424 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/modgolangv0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more0.40.0423
OSV records
DEBIAN-CVE-2026-56864GO-2026-6180
Also known as
BIT-golang-2026-56864

Charts affected

457 by stars
ChartLatestAffected imagesRadar Score
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/mod@v0.2.0
0.40.0

Open the chart page →

4,985
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

905
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

1,650
prometheuswenerme29.30.01 of 6See more

prometheus wenerme 29.30.0

1 of the 6 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

458
rancherwenerme2.15.12 of 2See more

rancher wenerme 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/mod@v0.36.0
0.40.0
rancher/shell:v0.8.1f293af9c635f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

1,456
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/mod@v0.22.0
0.40.0

Open the chart page →

9,381
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:latest690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

879

Container images carrying it

424 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/mod@v0.7.0
0.40.0
1
instill/api-gateway:9bfdc88b53eaa51c523
golang.org/x/mod@v0.29.0
0.40.0
1
instill/artifact-backend:b28766ac4a393e601ed
golang.org/x/mod@v0.32.0
0.40.0
1
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
golang.org/x/mod@v0.21.0
0.40.0
1
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/mod@v0.21.0
0.40.0
1
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
golang.org/x/mod@v0.17.0
0.40.0
1
ixsystems/truecommand:3.2.019c218455cd2
golang.org/x/mod@v0.26.0
0.40.0
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/mod@v0.7.0
0.40.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/mod@v0.11.0
0.40.0
1
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/mod@v0.35.0
0.40.0
1
kubearmor/kubearmor:stablea08141311045
golang.org/x/mod@v0.36.0
0.40.0
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/mod@v0.5.1
0.40.0
1
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
golang.org/x/mod@v0.25.0
0.40.0
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
golang.org/x/mod@v0.22.0
0.40.0
1
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/mod@v0.8.0
0.40.0
1
kusionstack/kusion:v0.14.0126c8f0b0976
golang.org/x/mod@v0.22.0
0.40.0
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
golang.org/x/mod@v0.35.0
0.40.0
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
golang.org/x/mod@v0.35.0
0.40.0
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
golang.org/x/mod@v0.35.0
0.40.0
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
golang.org/x/mod@v0.35.0
0.40.0
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
golang.org/x/mod@v0.35.0
0.40.0
1
layer5/meshery:stable-latest78a8be21bef3
golang.org/x/mod@v0.24.0
0.40.0
1
library/docker:28.5.2-dind2a232a42256f
golang.org/x/mod@v0.24.0
0.40.0
1
library/docker:29.7.2-dind3ef33f2e220b
golang.org/x/mod@v0.36.0
0.40.0
1
library/docker:27-dindaa3df78ecf32
golang.org/x/mod@v0.21.0
0.40.0
1
library/docker:26.1-dinddd43b430341a
golang.org/x/mod@v0.17.0
0.40.0
1
library/docker:dind-rootlesse17fa54c2ffd
golang.org/x/mod@v0.36.0
0.40.0
1
library/traefik:v2.11.00a5157f742d2
golang.org/x/mod@v0.14.0
0.40.0
1
library/traefik:3.3.5104204dadedf
golang.org/x/mod@v0.22.0
0.40.0
1
library/traefik:v2.10.11489caffaedb
golang.org/x/mod@v0.6.0
0.40.0
1
library/traefik:2.10.61957e3314f43
golang.org/x/mod@v0.12.0
0.40.0
1
library/traefik:2.5.62f603f8d3abe
golang.org/x/mod@v0.4.2
0.40.0
1
library/traefik:v3.6.1334d5089d0b41
golang.org/x/mod@v0.32.0
0.40.0
1
library/traefik:2.5.47d0228d19042
golang.org/x/mod@v0.4.2
0.40.0
1
library/traefik:v3.7.109c3b91d5fb77
golang.org/x/mod@v0.37.0
0.40.0
1
library/traefik:2.4.8eda951fd29a8
golang.org/x/mod@v0.3.0
0.40.0
1
linode/linode-cloud-controller-manager:v0.9.8cd8c17512206
golang.org/x/mod@v0.37.0
0.40.0
1
linuxserver/wireguard:latestbf03578ef731
golang.org/x/mod@v0.29.0
0.40.0
1
linuxserver/wireguard:1.0.20260223-r0-ls122dca67384e3e9
golang.org/x/mod@v0.29.0
0.40.0
1
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/mod@v0.29.0
0.40.0
1
livekit/ingress:v1.2.21ab01641b366
golang.org/x/mod@v0.14.0
0.40.0
1
livekit/livekit-server:v1.9.03602a85840d5
golang.org/x/mod@v0.24.0
0.40.0
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/mod@v0.28.0
0.40.0
1
longhornio/longhorn-manager:v1.12.0fd245bae2e82
golang.org/x/mod@v0.35.0
0.40.0
1
looplj/axonhub:latest2c71eeaef295
golang.org/x/mod@v0.38.0
0.40.0
1
lumenvox/file-store:7.138aa8711c9ef
golang.org/x/mod@v0.34.0
0.40.0
1
lumenvox/management-api:7.16420a6e7d6c2
golang.org/x/mod@v0.34.0
0.40.0
1
mattermost/mattermost-enterprise-edition:11.7ca5e5553a767
golang.org/x/mod@v0.37.0
0.40.0
1
megaease/easegress:latestfad1c7452958
golang.org/x/mod@v0.30.0
0.40.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.