GO-2026-5932None▾ SunlitThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.
If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.
golang.org/x/cryptoRefer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-29652High· 7.5golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
CVE-2026-56855Medium· 5.3Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
CVE-2024-45337NoneMisuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
CVE-2026-46598Medium· 5.3Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVE-2026-46597High· 7.5Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-39827Medium· 6.5Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh