CVE-2026-56865
HighAdvisory
Published 13 Aug 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.4
- base score, highest
- EPSS
- 0.001
- 1st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 453
- of 17,781 indexed, latest versions
- Container images
- 422
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Carried by container images the latest versions of 453 of 17,781 indexed charts deploy, on 422 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| golang.org/ | v0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more | 0.40.0 | 421 |
- OSV records
- DEBIAN-CVE-2026-56865GO-2026-6179
- Also known as
- BIT-golang-2026-56865
Charts affected
453 by stars
Container images carrying it
422 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| supabase/ | 385184459f57 | golang.org/ | 0.40.0 | 1 |
| supabase/ | ba4ddc594b0b | golang.org/ | 0.40.0 | 1 |
| sysadminsmedia/ | 56e880b62309 | golang.org/ | 0.40.0 | 1 |
| thmmniii/ | 86105349c1a3 | golang.org/ | 0.40.0 | 1 |
| treeverse/ | fb7a0d90f77e | golang.org/ | 0.40.0 | 1 |
| uptrace/ | 34a02c3b2d12 | golang.org/ | 0.40.0 | 1 |
| velero/ | 11459094b1b2 | golang.org/ | 0.40.0 | 1 |
| velero/ | 277fbfaf8dcf | golang.org/ | 0.40.0 | 1 |
| velero/ | 37396519f399 | golang.org/ | 0.40.0 | 1 |
| velero/ | 8d784580931c | golang.org/ | 0.40.0 | 1 |
| velero/ | e4d1e79be2ee | golang.org/ | 0.40.0 | 1 |
| wallarm/ | f1cb26db1f5b | golang.org/ | 0.40.0 | 1 |
| wallarm/ | a321bc974a19 | golang.org/ | 0.40.0 | 1 |
| wistefan/ | 3bd436164b51 | golang.org/ | 0.40.0 | 1 |
| gcr.io/ | 6efe04ba4e06 | golang.org/ | 0.40.0 | 1 |
| gcr.io/ | 5a0884f9a90c | golang.org/ | 0.40.0 | 1 |
| gcr.io/ | ea30f1ce8dc4 | golang.org/ | 0.40.0 | 1 |
| gcr.io/ | 784518ff3ee7 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | a6d99f323d30 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 6e9ced773732 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 7465f35b684c | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 8fbdd2479645 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 68e17a8aaa40 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 40f46bb38d0f | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 1aba0ffe55ea | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 9ab9a675c405 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | b6373349a301 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | cf2c16fac5b5 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 130c0b1b6fa3 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | df53e2c8998c | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | a058034ca006 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 8a8ec8d4c9ea | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | e7f9e8f1d565 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 951d71162065 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 3915d2e41e04 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 4e872bc016e8 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 79df4fb20322 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | dbdb3e524dea | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 7008df32715c | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 10ae596d296e | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 269d0e55ea97 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 0881d3c9359b | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 13964b29d63e | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 5d0656fce7d4 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 8186d6dd81f4 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | f579d00721b0 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | a43323732181 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 745504757300 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | 2f5be9cde5f9 | golang.org/ | 0.40.0 | 1 |
| ghcr.io/ | a0b272f6682a | golang.org/ | 0.40.0 | 1 |