StackRadar

CVE-2026-56865

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
453
of 17,781 indexed, latest versions
Container images
422
deployed by those charts
Fix available
1 of 2
affected packages

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

Carried by container images the latest versions of 453 of 17,781 indexed charts deploy, on 422 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/modgolangv0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more0.40.0421
OSV records
DEBIAN-CVE-2026-56865GO-2026-6179
Also known as
BIT-golang-2026-56865

Charts affected

453 by stars
ChartLatestAffected imagesRadar Score
argo-cdargoOfficialVerified publisher10.9.01 of 3See more

argo-cd argo 10.9.0

1 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/mod@v0.32.0
0.40.0

Open the chart page →

3,218
prometheusprometheus-communityOfficialVerified publisher29.29.01 of 6See more

prometheus prometheus-community 29.29.0

1 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

458
harborharborOfficialVerified publisher1.19.21 of 8See more

harbor harbor 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

1,650
longhornlonghorn1.12.11 of 3See more

longhorn longhorn 1.12.1

1 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.183b79f57043f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

554
gitlab-runnergitlabVerified publisher0.92.11 of 1See more

gitlab-runner gitlab 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

904
velerovmware-tanzu12.1.01 of 1See more

velero vmware-tanzu 12.1.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
velero/velero:v1.18.111459094b1b2
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

1,331
rancherrancher-stable2.15.12 of 2See more

rancher rancher-stable 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/mod@v0.36.0
0.40.0
rancher/shell:v0.8.1f293af9c635f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

1,456
kedakedacore2.20.23 of 3See more

keda kedacore 2.20.2

3 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.20.2fe74c7b88495
golang.org/x/mod@v0.36.0
0.40.0
ghcr.io/kedacore/keda-admission-webhooks:2.20.241f74102aba7
golang.org/x/mod@v0.36.0
0.40.0
ghcr.io/kedacore/keda-metrics-apiserver:2.20.227286536a8a7
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

873
artifact-hubartifact-hubVerified publisher1.23.04 of 7See more

artifact-hub artifact-hub 1.23.0

4 of the 7 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
golang.org/x/mod@v0.31.0
0.40.0
artifacthub/hub:v1.23.07d3a91c539dc
golang.org/x/mod@v0.37.0
0.40.0
artifacthub/scanner:v1.23.02d8365601f0e
golang.org/x/mod@v0.31.0
0.40.0
artifacthub/tracker:v1.23.05368d21a6e5c
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

10,755
argo-cdargo-cd-oci10.9.01 of 3See more

argo-cd argo-cd-oci 10.9.0

1 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/mod@v0.32.0
0.40.0

Open the chart page →

3,218
dexdexVerified publisher0.24.11 of 1See more

dex dex 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
golang.org/x/mod@v0.26.0
0.40.0

Open the chart page →

1,765
falcofalcosecurity9.1.02 of 3See more

falco falcosecurity 9.1.0

2 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
golang.org/x/mod@v0.35.0
0.40.0
falcosecurity/falcoctl:0.13.00eeb79adc580
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

5,227
alertmanagerprometheus-communityOfficialVerified publisher1.43.11 of 1See more

alertmanager prometheus-community 1.43.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

63
argo-eventsargoOfficialVerified publisher2.4.271 of 1See more

argo-events argo 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

969
openebsopenebsOfficialVerified publisher4.6.11 of 35See more

openebs openebs 4.6.1

1 of the 35 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/mod@v0.24.0
0.40.0

Open the chart page →

23,894
corednscorednsVerified publisher1.47.11 of 1See more

coredns coredns 1.47.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
coredns/coredns:1.14.6900f9c109f7a
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

330
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/mod@v0.4.2
0.40.0

Open the chart page →

2,059
openfaasopenfaas15.0.131 of 6See more

openfaas openfaas 15.0.13

1 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

3,543
flux2fluxcd-community2.19.02 of 7See more

flux2 fluxcd-community 2.19.0

2 of the 7 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/notification-controller:v1.9.29ce503e7bcb8
golang.org/x/mod@v0.36.0
0.40.0
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

2,951
policy-reporterpolicy-reporterOfficialVerified publisher3.10.01 of 1See more

policy-reporter policy-reporter 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:3.10.0a77e93fe5117
golang.org/x/mod@v0.39.0
0.40.0

Open the chart page →

26
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
golang.org/x/mod@v0.33.0
0.40.0

Open the chart page →

6,342
portainerportainer245.0.01 of 1See more

portainer portainer 245.0.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.45.0511f3f06c96f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

277
atlantisatlantis6.15.01 of 1See more

atlantis atlantis 6.15.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
golang.org/x/mod@v0.33.0
0.40.0

Open the chart page →

1,891
codercoder-v2OfficialVerified publisher2.37.11 of 1See more

coder coder-v2 2.37.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.37.10c6994bb4c5a
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

187
flaggerflagger1.45.01 of 1See more

flagger flagger 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger:1.45.015b372d35012
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

222
semaphoresemaphoreuiOfficialVerified publisher16.2.21 of 1See more

semaphore semaphoreui 16.2.2

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.18.3e9260bfa8255
golang.org/x/mod@v0.30.0
0.40.0

Open the chart page →

2,221
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

7,568
prometheus-mongodb-exporterprometheus-communityVerified publisher3.22.01 of 1See more

prometheus-mongodb-exporter prometheus-community 3.22.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
percona/mongodb_exporter:0.53.00214e482b2cd
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

231
node-local-dnsdeliveryheroVerified publisher2.9.21 of 1See more

node-local-dns deliveryhero 2.9.2

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/mod@v0.28.0
0.40.0

Open the chart page →

1,685
rancherrancher-latest2.15.12 of 2See more

rancher rancher-latest 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/mod@v0.36.0
0.40.0
rancher/shell:v0.8.1f293af9c635f
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

1,456
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/mod@v0.29.0
0.40.0

Open the chart page →

3,157
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/mod@v0.24.0
0.40.0

Open the chart page →

874
oktetooktetoOfficialVerified publisher0.0.0-2026-08-032 of 10See more

okteto okteto 0.0.0-2026-08-03

2 of the 10 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-03244f87e8c52d
golang.org/x/mod@v0.38.0
0.40.0
ghcr.io/okteto/buildkit:0.0.0-2026-08-0314527ca5d2a9
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

5,750
hydraory0.64.01 of 2See more

hydra ory 0.64.0

1 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/mod@v0.30.0
0.40.0

Open the chart page →

1,156
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
concourse/concourse:8.3.040a143ce5873
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

2,022
dynatrace-operatordynatraceVerified publisher1.10.21 of 1See more

dynatrace-operator dynatrace 1.10.2

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

147
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/mod@v0.18.0
0.40.0

Open the chart page →

16,251
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
golang.org/x/mod@v0.30.0
0.40.0

Open the chart page →

866
hpe-csi-driverhpe-storageVerified publisher3.3.01 of 14See more

hpe-csi-driver hpe-storage 3.3.0

1 of the 14 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.3.0e58e22427b38
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

1,615
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/mod@v0.27.0
0.40.0

Open the chart page →

2,321
beylagrafana1.16.111 of 1See more

beyla grafana 1.16.11

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/beyla:3.32.03ff0f7cf2bbf
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

123
helm-dashboardkomodorVerified publisher2.0.71 of 1See more

helm-dashboard komodor 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

308
kubescape-operatorkubescape1.40.43 of 6See more

kubescape-operator kubescape 1.40.4

3 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/kubescape/kubescape:v4.0.1358651dce3376
golang.org/x/mod@v0.38.0
0.40.0
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
golang.org/x/mod@v0.37.0
0.40.0
quay.io/kubescape/operator:v0.2.16901b2694425e9
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

920
spirespiffeVerified publisher0.30.21 of 10See more

spire spiffe 0.30.2

1 of the 10 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

1,640
bytebasebytebase1.1.51 of 1See more

bytebase bytebase 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
bytebase/bytebase:latest9fcde38c0d5f
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

435
ansible-semaphorecloudhippieVerified publisher15.2.101 of 1See more

ansible-semaphore cloudhippie 15.2.10

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
golang.org/x/mod@v0.24.0
0.40.0

Open the chart page →

1,235
codefreshcodefresh-onpremOfficialVerified publisher2.12.131 of 42See more

codefresh codefresh-onprem 2.12.13

1 of the 42 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

14,956
gitlab-operatorgitlabVerified publisher3.3.21 of 1See more

gitlab-operator gitlab 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.3.242dd426130a9
golang.org/x/mod@v0.39.0
0.40.0

Open the chart page →

145
lakefslakefsVerified publisher1.12.281 of 1See more

lakefs lakefs 1.12.28

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
treeverse/lakefs:1.86.0fb7a0d90f77e
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

395
supabasetokens-studioVerified publisher1.0.02 of 14See more

supabase tokens-studio 1.0.0

2 of the 14 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/mod@v0.21.0
0.40.0
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/mod@v0.17.0
0.40.0

Open the chart page →

23,123

Container images carrying it

422 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/mod@v0.4.2
0.40.0
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/mod@v0.4.2
0.40.0
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/mod@v0.12.0
0.40.0
1
quay.io/kubescape/kubescape:v4.0.1358651dce3376
golang.org/x/mod@v0.38.0
0.40.0
1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
golang.org/x/mod@v0.37.0
0.40.0
1
quay.io/kubescape/operator:v0.2.16901b2694425e9
golang.org/x/mod@v0.35.0
0.40.0
1
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/mod@v0.24.0
0.40.0
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
golang.org/x/mod@v0.34.0
0.40.0
1
quay.io/piraeusdatastore/nri-volume-qos:v0.1.3cbe3e1ea2b6a
golang.org/x/mod@v0.36.0
0.40.0
1
quay.io/prometheus/alertmanager:v0.24.0088464f949de
golang.org/x/mod@v0.5.1
0.40.0
1
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
golang.org/x/mod@v0.34.0
0.40.0
1
quay.io/prometheus/alertmanager:v0.31.188b605de9aba
golang.org/x/mod@v0.32.0
0.40.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
golang.org/x/mod@v0.12.0
0.40.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
golang.org/x/mod@v0.4.2
0.40.0
1
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/mod@v0.10.0
0.40.0
1
quay.io/stackrox-io/stackrox-operator:4.11.3e12f4ca30515
golang.org/x/mod@v0.38.0
0.40.0
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.3.242dd426130a9
golang.org/x/mod@v0.39.0
0.40.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/mod@v0.35.0
0.40.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
golang.org/x/mod@v0.39.0
0.40.0
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
golang.org/x/mod@v0.36.0
0.40.0
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
golang.org/x/mod@v0.29.0
0.40.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/mod@v0.28.0
0.40.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.