VulnSea

x has 17 CVEs on record between 2022 and 2026. Cadence is steady at roughly 4 per quarter. The busiest recent month was May 2026 with 4. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: golang.org/x/net (7), golang.org/x/crypto (4), golang.org/x/image (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
4 prev 4

Products

  • golang.org/x/net 7
  • golang.org/x/crypto 4
  • golang.org/x/image 3
  • golang.org/x/oauth2 1
  • golang.org/x/text 1
  • libxfont 1
17
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

x vulnerabilities

CVEs affecting x, newest first. Open any entry for full detail, references, and exploit status.

17 CVEsRSS

CVE-2026-46603None
1mo ago

Excessive memory allocation during VP8L decoding in golang.org/x/image

Excessive memory allocation during VP8L decoding in golang.org/x/image

Sunlitx · golang.org/x/imageEPSS 0.42%via OSV
CVE-2026-56002High· 8.5
2mo ago

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

Twilightx · libxfontEPSS 0.43%via NVD
GO-2026-5932None
2mo ago

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

Sunlitx · golang.org/x/cryptovia OSV
CVE-2026-46599High· 7.5
2mo ago

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

Twilightx · golang.org/x/imageEPSS 0.35%via GHSA
CVE-2026-25680Medium· 6.5
3mo ago

Go Net HTML parser is vulnerable to denial of service

Go Net HTML parser is vulnerable to denial of service

Sunlitx · golang.org/x/netEPSS 0.33%via OSV
CVE-2026-27136None
4mo ago

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-25681None
4mo ago

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-46597High· 7.5
4mo ago

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Twilightx · golang.org/x/cryptoEPSS 0.47%via OSV
CVE-2026-33809Medium· 5.3
6mo ago

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

Sunlitx · golang.org/x/imageEPSS 0.33%via OSV
CVE-2025-22868High· 7.5
1y ago

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Twilightx · golang.org/x/oauth2EPSS 0.87%via OSV
CVE-2024-45337NonePoC
1y ago

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Twilightx · golang.org/x/cryptoEPSS 3.2%via OSV
CVE-2023-39325High· 7.5PoC
2y ago

HTTP/2 rapid reset can cause excessive work in net/http

HTTP/2 rapid reset can cause excessive work in net/http

Midnightx · golang.org/x/netEPSS 3.8%via OSV
CVE-2023-3978Medium· 6.1
3y ago

Improper rendering of text nodes in golang.org/x/net/html

Improper rendering of text nodes in golang.org/x/net/html

Sunlitx · golang.org/x/netEPSS 0.85%via OSV
CVE-2022-32149High· 7.5
3y ago

golang.org/x/text/language Denial of service via crafted Accept-Language header

golang.org/x/text/language Denial of service via crafted Accept-Language header

Twilightx · golang.org/x/textEPSS 1.6%via OSV
CVE-2022-27664High· 7.5
4y ago

golang.org/x/net/http2 Denial of Service vulnerability

golang.org/x/net/http2 Denial of Service vulnerability

Twilightx · golang.org/x/netEPSS 3.3%via OSV
CVE-2020-29652High· 7.5
4y ago

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

Twilightx · golang.org/x/cryptoEPSS 3.3%via OSV
CVE-2018-17847High· 7.5
4y ago

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

Twilightx · golang.org/x/netEPSS 2.4%via OSV
x vulnerabilities (CVEs) · VulnSea