StackRadar

CVE-2026-56864

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
457
of 17,787 indexed, latest versions
Container images
424
deployed by those charts
Fix available
1 of 2
affected packages

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Carried by container images the latest versions of 457 of 17,787 indexed charts deploy, on 424 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/modgolangv0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more0.40.0423
OSV records
DEBIAN-CVE-2026-56864GO-2026-6180
Also known as
BIT-golang-2026-56864

Charts affected

457 by stars
ChartLatestAffected imagesRadar Score
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/mod@v0.2.0
0.40.0

Open the chart page →

4,985
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

905
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

1,650
prometheuswenerme29.30.01 of 6See more

prometheus wenerme 29.30.0

1 of the 6 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

458
rancherwenerme2.15.12 of 2See more

rancher wenerme 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/mod@v0.36.0
0.40.0
rancher/shell:v0.8.1f293af9c635f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

1,456
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/mod@v0.22.0
0.40.0

Open the chart page →

9,381
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-56864.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:latest690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

879

Container images carrying it

424 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/hpestorage/csi-driver:v3.3.0e58e22427b38
golang.org/x/mod@v0.38.0
0.40.0
1
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
golang.org/x/mod@v0.30.0
0.40.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/mod@v0.4.2
0.40.0
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/mod@v0.4.2
0.40.0
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/mod@v0.12.0
0.40.0
1
quay.io/kubescape/kubescape:v4.0.1358651dce3376
golang.org/x/mod@v0.38.0
0.40.0
1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
golang.org/x/mod@v0.37.0
0.40.0
1
quay.io/kubescape/operator:v0.2.16901b2694425e9
golang.org/x/mod@v0.35.0
0.40.0
1
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/mod@v0.24.0
0.40.0
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
golang.org/x/mod@v0.34.0
0.40.0
1
quay.io/piraeusdatastore/nri-volume-qos:v0.1.3cbe3e1ea2b6a
golang.org/x/mod@v0.36.0
0.40.0
1
quay.io/prometheus/alertmanager:v0.24.0088464f949de
golang.org/x/mod@v0.5.1
0.40.0
1
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
golang.org/x/mod@v0.34.0
0.40.0
1
quay.io/prometheus/alertmanager:v0.31.188b605de9aba
golang.org/x/mod@v0.32.0
0.40.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
golang.org/x/mod@v0.12.0
0.40.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
golang.org/x/mod@v0.4.2
0.40.0
1
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/mod@v0.10.0
0.40.0
1
quay.io/stackrox-io/stackrox-operator:4.11.3e12f4ca30515
golang.org/x/mod@v0.38.0
0.40.0
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.3.242dd426130a9
golang.org/x/mod@v0.39.0
0.40.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/mod@v0.35.0
0.40.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
golang.org/x/mod@v0.39.0
0.40.0
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
golang.org/x/mod@v0.36.0
0.40.0
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
golang.org/x/mod@v0.29.0
0.40.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/mod@v0.28.0
0.40.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.