Dependency scanning
Check whether golang.org/x/crypto is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-39835
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
CVE-2026-42508
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
CVE-2026-46595
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
CVE-2026-39830
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
CVE-2026-39832
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
CVE-2026-39828
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
CVE-2026-39829
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
GO-2026-5932
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-39829
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
CVE-2026-39832
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVE-2026-39835
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
CVE-2026-39830
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
CVE-2023-48795
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
CVE-2023-48795
Man-in-the-middle attacker can compromise integrity of secure channel in golang.org/x/crypto
CVE-2026-39834
golang.org/x/crypto vulnerable to infinite loop on large channel writes
CVE-2026-39827
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS
CVE-2026-46598
golang.org/x/crypto: Invoking pathological inputs can lead to client panic
CVE-2026-39833
golang.org/x/crypto doesn't enforce invoking key constraints
CVE-2026-46597
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
CVE-2026-39831
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
CVE-2026-42508
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
CVE-2026-46595
Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
CVE-2026-39827
Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
CVE-2026-46597
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-39834
Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
CVE-2026-39828
Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
CVE-2026-39831
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
CVE-2026-46598
Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVE-2026-39833
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
CVE-2022-30636
Limited directory traversal vulnerability on Windows in golang.org/x/crypto
CVE-2025-47913
Potential denial of service in golang.org/x/crypto/ssh/agent
CVE-2025-58181
Unbounded memory consumption in golang.org/x/crypto/ssh
CVE-2025-47914
Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent
CVE-2025-58181
golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption
CVE-2025-47914
golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read
CVE-2024-45337
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
CVE-2024-45337
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
CVE-2025-22869
golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange
CVE-2025-22869
Potential denial of service in golang.org/x/crypto
CVE-2019-11841
Golang/x/crypto message forgery vulnerability
CVE-2019-11840
Insufficiently random values in golang.org/x/crypto/salsa20
CVE-2020-7919
Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyte
CVE-2022-27191
golang.org/x/crypto/ssh Denial of service via crafted Signer
CVE-2021-43565
Panic on malformed packets in golang.org/x/crypto/ssh
CVE-2020-7919
Helm uses crypto package vulnerable to panic from malformed X.509 certificate
CVE-2021-43565
x/crypto/ssh vulnerable to panic via malformed packets
CVE-2020-9283
Panic due to improper verification of cryptographic signatures in golang.org/x/crypto/ssh
CVE-2020-29652
golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
CVE-2020-29652
Panic on crafted authentication request message in golang.org/x/crypto/ssh
CVE-2019-11841
Misleading message verification in golang.org/x/crypto/openpgp/clearsign
CVE-2019-11840
golang.org/x/crypto/salsa20/salsa uses insufficiently random values
CVE-2022-27191
Denial of service via crafted Signer in golang.org/x/crypto/ssh
CVE-2020-9283
Improper Verification of Cryptographic Signature in golang.org/x/crypto
CVE-2017-3204
Man-in-the-middle attack in golang.org/x/crypto/ssh
CVE-2017-3204
golang.org/x/crypto/ssh Man-in-the-Middle attack
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes