golang.org/x/crypto vulnerabilities
CVEs whose affected-version data names the golang.org/x/crypto package (go, rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
GO-2026-5932NoneThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
▾ Sunlitx · golang.org/x/cryptovia OSV
CVE-2026-46597High· 7.5Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
▾ Twilightx · golang.org/x/cryptoEPSS 0.47%via OSV
CVE-2024-45337NonePoCMisuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
▾ Twilightx · golang.org/x/cryptoEPSS 3.2%via OSV
CVE-2023-48795Medium· 5.9PoCPrefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
▾ Twilightrussh · russhEPSS 93%via OSV
CVE-2020-29652High· 7.5golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
▾ Twilightx · golang.org/x/cryptoEPSS 3.3%via OSV