golang.org/x/crypto vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-46595Criticalgolang.org/x/crypto: golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcementCVE-2026-42508Criticalgolang.org/x/crypto: golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked statusCVE-2026-39834Criticalgolang.org/x/crypto: golang.org/x/crypto vulnerable to infinite loop on large channel writesCVE-2026-39831Criticalgolang.org/x/crypto: golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassedCVE-2026-39829Highgolang.org/x/crypto: golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoSCVE-2026-39830Criticalgolang.org/x/crypto: golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responsesCVE-2026-39827Mediumgolang.org/x/crypto: golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoSCVE-2026-39835Mediumgolang.org/x/crypto: golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flowCVE-2026-39828Mediumgolang.org/x/crypto: golang.org/x/crypto vulnerable to invoking bypass of certificate restrictionsCVE-2026-46597Highgolang.org/x/crypto: golang.org/x/crypto: Invoking byte arithmetic causes underflow and panicCVE-2026-39832Criticalgolang.org/x/crypto: golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keysCVE-2026-39833Criticalgolang.org/x/crypto: golang.org/x/crypto doesn't enforce invoking key constraintsCVE-2026-46598Mediumgolang.org/x/crypto: golang.org/x/crypto: Invoking pathological inputs can lead to client panicCVE-2025-47914Mediumgolang.org/x/crypto: golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds readCVE-2025-58181Mediumgolang.org/x/crypto: golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumptionCVE-2025-22869Highgolang.org/x/crypto: golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key ExchangeCVE-2024-45337Criticalgolang.org/x/crypto: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/cryptoCVE-2023-48795Mediumrussh: Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka TerrapinCVE-2017-3204Highgolang.org/x/crypto: golang.org/x/crypto/ssh Man-in-the-Middle attackCVE-2021-43565Highgolang.org/x/crypto: x/crypto/ssh vulnerable to panic via malformed packetsCVE-2020-29652Highgolang.org/x/crypto: golang.org/x/crypto/ssh NULL Pointer Dereference vulnerabilityCVE-2019-11841Mediumgolang.org/x/crypto: Golang/x/crypto message forgery vulnerabilityCVE-2019-11840Mediumgolang.org/x/crypto: golang.org/x/crypto/salsa20/salsa uses insufficiently random valuesCVE-2022-27191Highgolang.org/x/crypto: golang.org/x/crypto/ssh Denial of service via crafted SignerCVE-2020-7919Highgithub.com/helm/helm: Helm uses crypto package vulnerable to panic from malformed X.509 certificate

Stop the waste.
Protect your environment with Kodem.