StackRadar

CVE-2026-56864

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
457
of 17,787 indexed, latest versions
Container images
424
deployed by those charts
Fix available
1 of 2
affected packages

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Carried by container images the latest versions of 457 of 17,787 indexed charts deploy, on 424 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/modgolangv0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more0.40.0423
OSV records
DEBIAN-CVE-2026-56864GO-2026-6180
Also known as
BIT-golang-2026-56864

Charts affected

457 by stars
ChartLatestAffected imagesRadar Score
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/mod@v0.2.0
0.40.0

Open the chart page →

4,985
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

905
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

1,650
prometheuswenerme29.30.01 of 6See more

prometheus wenerme 29.30.0

1 of the 6 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

458
rancherwenerme2.15.12 of 2See more

rancher wenerme 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/mod@v0.36.0
0.40.0
rancher/shell:v0.8.1f293af9c635f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

1,456
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/mod@v0.22.0
0.40.0

Open the chart page →

9,381
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:latest690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

879

Container images carrying it

424 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/mod@v0.14.0
0.40.0
1
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
golang.org/x/mod@v0.30.0
0.40.0
1
ghcr.io/fluxcd/flagger:1.45.015b372d35012
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/fluxcd/notification-controller:v1.9.29ce503e7bcb8
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/mod@v0.22.0
0.40.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/honeycombio/refinery/refinery:3.4.0d437676941d6
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/mod@v0.27.0
0.40.0
1
ghcr.io/inlets/inlets-operator:0.17.2208265c006973
golang.org/x/mod@v0.34.0
0.40.0
1
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
golang.org/x/mod@v0.27.0
0.40.0
1
ghcr.io/jarodr47/portager:0.5.06a7a61b37568
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
golang.org/x/mod@v0.20.0
0.40.0
1
ghcr.io/kedacore/keda:2.20.2fe74c7b88495
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/kedacore/keda-admission-webhooks:2.20.241f74102aba7
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/kedacore/keda-metrics-apiserver:2.20.227286536a8a7
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
golang.org/x/mod@v0.21.0
0.40.0
1
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
golang.org/x/mod@v0.26.0
0.40.0
1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/mod@v0.6.0-dev.0.20220106191415-9b9b3d81d5e3
0.40.0
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/mod@v0.6.0-dev.0.20220106191415-9b9b3d81d5e3
0.40.0
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/policy-reporter:3.10.0a77e93fe5117
golang.org/x/mod@v0.39.0
0.40.0
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/lockdep/stackradar-scanner:0.3.0dd8a35d50c2d
golang.org/x/mod@v0.32.0
0.40.0
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/mod@v0.8.0
0.40.0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/mod@v0.12.0
0.40.0
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/mod@v0.10.0
0.40.0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/loft-sh/vcluster-hpm:0.2.7f65f6810ea23
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/loft-sh/vcluster-platform:4.12.0ef92da4621e6
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/mod@v0.14.0
0.40.0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/mod@v0.20.0
0.40.0
1
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/okteto/backend:0.0.0-2026-08-17629bdce31b4d
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-03:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
golang.org/x/mod@v0.12.0
0.40.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.