StackRadar

CVE-2026-56864

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
457
of 17,787 indexed, latest versions
Container images
424
deployed by those charts
Fix available
1 of 2
affected packages

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Carried by container images the latest versions of 457 of 17,787 indexed charts deploy, on 424 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/modgolangv0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more0.40.0423
OSV records
DEBIAN-CVE-2026-56864GO-2026-6180
Also known as
BIT-golang-2026-56864

Charts affected

457 by stars
ChartLatestAffected imagesRadar Score
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/mod@v0.2.0
0.40.0

Open the chart page →

4,985
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

905
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

1,650
prometheuswenerme29.30.01 of 6See more

prometheus wenerme 29.30.0

1 of the 6 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

458
rancherwenerme2.15.12 of 2See more

rancher wenerme 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/mod@v0.36.0
0.40.0
rancher/shell:v0.8.1f293af9c635f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

1,456
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/mod@v0.22.0
0.40.0

Open the chart page →

9,381
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:latest690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

879

Container images carrying it

424 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-feature/flagd:v0.16.032234e63c1d0
golang.org/x/mod@v0.33.0
0.40.0
1
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/mod@v0.19.0
0.40.0
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
golang.org/x/mod@v0.30.0
0.40.0
1
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
golang.org/x/mod@v0.17.0
0.40.0
1
ghcr.io/open-telemetry/demo:3.0.0-product-catalog278aff685646
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
golang.org/x/mod@v0.17.0
0.40.0
1
ghcr.io/open-telemetry/demo:3.0.0-checkout3d18cb304a6a
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/open-telemetry/opentelemetry-ebpf-instrumentation/ebpf-instrument:v0.9.026f82b148dfe
golang.org/x/mod@v0.35.0
0.40.0
1
ghcr.io/opnpulse/perses:v2026.4.24b880da90aa1a
golang.org/x/mod@v0.27.0
0.40.0
1
ghcr.io/performancecopilot/archive-analysis:latest8de11e2363fc
golang.org/x/mod@v0.12.0
0.40.0
1
ghcr.io/riotkit-org/backup-maker-controller:v0.1.262370545ba3d
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
golang.org/x/mod@v0.33.0
0.40.0
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
golang.org/x/mod@v0.26.0
0.40.0
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
golang.org/x/mod@v0.19.0
0.40.0
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
golang.org/x/mod@v0.24.0
0.40.0
1
ghcr.io/sigstore/rekor-tiles/gcp:v2.2.1e401cfe033c9
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
golang.org/x/mod@v0.18.0
0.40.0
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
golang.org/x/mod@v0.18.0
0.40.0
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
golang.org/x/mod@v0.18.0
0.40.0
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/mod@v0.30.0
0.40.0
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
golang.org/x/mod@v0.17.0
0.40.0
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
golang.org/x/mod@v0.17.0
0.40.0
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
golang.org/x/mod@v0.13.0
0.40.0
1
ghcr.io/transparency-dev/tesseract/posix:v0.1.2b044edd23888
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/mod@v0.22.0
0.40.0
1
ghcr.io/voidmind-io/voidllm:0.0.250df11dd20c28
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
golang.org/x/mod@v0.22.0
0.40.0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
golang.org/x/mod@v0.17.0
0.40.0
1
ghcr.io/zapier/kubechecks:latest60cea46ce830
golang.org/x/mod@v0.37.0
0.40.0
1
mcr.microsoft.com/oss/v2/nvidia/k8s-device-plugin:v0.18.2-125a4e52c87bb9
golang.org/x/mod@v0.37.0
0.40.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
golang.org/x/mod@v0.29.0
0.40.0
1
public.ecr.aws/diagrid-dev/diagrid-dashboard:latestf1348a65664a
golang.org/x/mod@v0.35.0
0.40.0
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
golang.org/x/mod@v0.38.0
0.40.0
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
golang.org/x/mod@v0.20.0
0.40.0
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/mod@v0.38.0
0.40.0
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
golang.org/x/mod@v0.27.0
0.40.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/mod@v0.20.0
0.40.0
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/mod@v0.24.0
0.40.0
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
golang.org/x/mod@v0.32.0
0.40.0
1
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
golang.org/x/mod@v0.33.0
0.40.0
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/mod@v0.5.1-0.20210830214625-1b1db11ec8f4
0.40.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/mod@v0.6.0-dev.0.20220106191415-9b9b3d81d5e3
0.40.0
1
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/mod@v0.36.0
0.40.0
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
golang.org/x/mod@v0.36.0
0.40.0
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
golang.org/x/mod@v0.31.0
0.40.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.