StackRadar

CVE-2026-56864

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
457
of 17,787 indexed, latest versions
Container images
424
deployed by those charts
Fix available
1 of 2
affected packages

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Carried by container images the latest versions of 457 of 17,787 indexed charts deploy, on 424 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/modgolangv0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more0.40.0423
OSV records
DEBIAN-CVE-2026-56864GO-2026-6180
Also known as
BIT-golang-2026-56864

Charts affected

457 by stars
ChartLatestAffected imagesRadar Score
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/mod@v0.2.0
0.40.0

Open the chart page →

4,985
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

905
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

1,650
prometheuswenerme29.30.01 of 6See more

prometheus wenerme 29.30.0

1 of the 6 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

458
rancherwenerme2.15.12 of 2See more

rancher wenerme 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/mod@v0.36.0
0.40.0
rancher/shell:v0.8.1f293af9c635f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

1,456
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/mod@v0.22.0
0.40.0

Open the chart page →

9,381
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:latest690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

879

Container images carrying it

424 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/mod@v0.14.0
0.40.0
1
stashapp/stash:latest24dbd7607174
golang.org/x/mod@v0.3.0
0.40.0
1
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/mod@v0.34.0
0.40.0
1
supabase/gotrue:v2.189.0385184459f57
golang.org/x/mod@v0.34.0
0.40.0
1
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/mod@v0.17.0
0.40.0
1
sysadminsmedia/homebox:0.26.056e880b62309
golang.org/x/mod@v0.37.0
0.40.0
1
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/mod@v0.11.0
0.40.0
1
treeverse/lakefs:1.86.0fb7a0d90f77e
golang.org/x/mod@v0.36.0
0.40.0
1
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/mod@v0.25.0
0.40.0
1
velero/velero:v1.18.111459094b1b2
golang.org/x/mod@v0.35.0
0.40.0
1
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/mod@v0.4.2
0.40.0
1
velero/velero:v1.18.237396519f399
golang.org/x/mod@v0.36.0
0.40.0
1
velero/velero:v1.8.18d784580931c
golang.org/x/mod@v0.4.2
0.40.0
1
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/mod@v0.30.0
0.40.0
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
golang.org/x/mod@v0.29.0
0.40.0
1
wallarm/gateway-control-plane:0.2.0a321bc974a19
golang.org/x/mod@v0.27.0
0.40.0
1
wistefan/vcbackend:0.0.13bd436164b51
golang.org/x/mod@v0.7.0
0.40.0
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/mod@v0.22.0
0.40.0
1
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
golang.org/x/mod@v0.29.0
0.40.0
1
gcr.io/knative-releases/knative.dev/operator/cmd/operator:v1.22.1ea30f1ce8dc4
golang.org/x/mod@v0.35.0
0.40.0
1
gcr.io/projectsigstore/cosigned784518ff3ee7
golang.org/x/mod@v0.6.0-dev.0.20220106191415-9b9b3d81d5e3
0.40.0
1
ghcr.io/0xerr0r/blocky:v0.29.0a6d99f323d30
golang.org/x/mod@v0.32.0
0.40.0
1
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
golang.org/x/mod@v0.20.0
0.40.0
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/mod@v0.17.0
0.40.0
1
ghcr.io/appscode/cluster-presets:v0.0.128fbdd2479645
golang.org/x/mod@v0.35.0
0.40.0
1
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/attestkeep/attestkeep-k8s:1.1.040f46bb38d0f
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/mod@v0.21.0
0.40.0
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/mod@v0.13.0
0.40.0
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
golang.org/x/mod@v0.26.0
0.40.0
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/mod@v0.22.0
0.40.0
1
ghcr.io/bodgit/nri-plugin-runtime:v0.0.3130c0b1b6fa3
golang.org/x/mod@v0.32.0
0.40.0
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/mod@v0.13.0
0.40.0
1
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
golang.org/x/mod@v0.33.0
0.40.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
golang.org/x/mod@v0.28.0
0.40.0
1
ghcr.io/chronicleprotocol/ghost:0.78.5951d71162065
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/mod@v0.24.0
0.40.0
1
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
golang.org/x/mod@v0.29.0
0.40.0
1
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/mod@v0.29.0
0.40.0
1
ghcr.io/ckotzbauer/sbom-operator:0.45.2dbdb3e524dea
golang.org/x/mod@v0.39.0
0.40.0
1
ghcr.io/ckotzbauer/vulnerability-operator:0.28.167008df32715c
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/coder/coder-logstream-kube:v0.0.1510ae596d296e
golang.org/x/mod@v0.33.0
0.40.0
1
ghcr.io/comet-ml/opik/opik-python-backend:2.2.61df70104803cb
golang.org/x/mod@v0.34.0
0.40.0
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/mod@v0.23.0
0.40.0
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
golang.org/x/mod@v0.26.0
0.40.0
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/mod@v0.23.0
0.40.0
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/mod@v0.10.0
0.40.0
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/mod@v0.8.0
0.40.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.