go

golang.org/x/crypto

View on go registry
55 Total advisories
55 Vulnerabilities
0 Malware

Dependency scanning

Check whether golang.org/x/crypto is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.3
Go

CVE-2026-39835

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

CRITICAL 9.1
Go

CVE-2026-42508

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

CRITICAL 10.0
Go

CVE-2026-46595

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

CRITICAL 9.1
Go

CVE-2026-39830

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CRITICAL 9.1
Go

CVE-2026-39832

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

MEDIUM 6.3
Go

CVE-2026-39828

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

HIGH 7.5
Go

CVE-2026-39829

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

UNKNOWN
Go

GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

UNKNOWN
Go

CVE-2026-39829

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-39832

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

UNKNOWN
Go

CVE-2026-39835

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-39830

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

MEDIUM 5.9
crates.io

CVE-2023-48795

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

UNKNOWN
Go

CVE-2023-48795

Man-in-the-middle attacker can compromise integrity of secure channel in golang.org/x/crypto

CRITICAL 9.1
Go

CVE-2026-39834

golang.org/x/crypto vulnerable to infinite loop on large channel writes

MEDIUM 6.5
Go

CVE-2026-39827

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

MEDIUM 5.3
Go

CVE-2026-46598

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

CRITICAL 9.1
Go

CVE-2026-39833

golang.org/x/crypto doesn't enforce invoking key constraints

HIGH 7.5
Go

CVE-2026-46597

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

CRITICAL 9.1
Go

CVE-2026-39831

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

UNKNOWN
Go

CVE-2026-42508

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

UNKNOWN
Go

CVE-2026-46595

Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-39827

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-46597

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-39834

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-39828

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-39831

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2026-46598

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

UNKNOWN
Go

CVE-2026-39833

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

UNKNOWN
Go

CVE-2022-30636

Limited directory traversal vulnerability on Windows in golang.org/x/crypto

UNKNOWN
Go

CVE-2025-47913

Potential denial of service in golang.org/x/crypto/ssh/agent

UNKNOWN
Go

CVE-2025-58181

Unbounded memory consumption in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2025-47914

Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent

MEDIUM 5.3
Go

CVE-2025-58181

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

MEDIUM 5.3
Go

CVE-2025-47914

golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read

UNKNOWN
Go

CVE-2024-45337

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

CRITICAL 9.1
Go

CVE-2024-45337

Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

HIGH 7.5
Go

CVE-2025-22869

golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange

UNKNOWN
Go

CVE-2025-22869

Potential denial of service in golang.org/x/crypto

MEDIUM 5.9
Go

CVE-2019-11841

Golang/x/crypto message forgery vulnerability

UNKNOWN
Go

CVE-2019-11840

Insufficiently random values in golang.org/x/crypto/salsa20

UNKNOWN
Go

CVE-2020-7919

Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyte

HIGH 7.5
Go

CVE-2022-27191

golang.org/x/crypto/ssh Denial of service via crafted Signer

UNKNOWN
Go

CVE-2021-43565

Panic on malformed packets in golang.org/x/crypto/ssh

HIGH 7.5
Go

CVE-2020-7919

Helm uses crypto package vulnerable to panic from malformed X.509 certificate

HIGH 7.5
Go

CVE-2021-43565

x/crypto/ssh vulnerable to panic via malformed packets

UNKNOWN
Go

CVE-2020-9283

Panic due to improper verification of cryptographic signatures in golang.org/x/crypto/ssh

HIGH 7.5
Go

CVE-2020-29652

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

UNKNOWN
Go

CVE-2020-29652

Panic on crafted authentication request message in golang.org/x/crypto/ssh

UNKNOWN
Go

CVE-2019-11841

Misleading message verification in golang.org/x/crypto/openpgp/clearsign

MEDIUM 5.9
Go

CVE-2019-11840

golang.org/x/crypto/salsa20/salsa uses insufficiently random values

UNKNOWN
Go

CVE-2022-27191

Denial of service via crafted Signer in golang.org/x/crypto/ssh

HIGH 7.5
Go

CVE-2020-9283

Improper Verification of Cryptographic Signature in golang.org/x/crypto

UNKNOWN
Go

CVE-2017-3204

Man-in-the-middle attack in golang.org/x/crypto/ssh

HIGH 8.1
Go

CVE-2017-3204

golang.org/x/crypto/ssh Man-in-the-Middle attack

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes