Skip to content
RequestGuard Vulnerabilities
Pricing

golang.org/x/crypto

Go package metadata, published advisories, affected versions, and known-exploitation evidence.

Go latest v0.57.0

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

v0.57.0

Published advisories match this version

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

32 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

32

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

Affected range

SEMVER: introduced 0; fixed 0.0.0-20201216223049-8b5274cf687f

Fixed versions: 0.0.0-20201216223049-8b5274cf687f

Improper Verification of Cryptographic Signature in golang.org/x/crypto

Affected range

SEMVER: introduced 0; fixed 0.0.0-20200220183623-bac4c82f6975

Fixed versions: 0.0.0-20200220183623-bac4c82f6975

Helm uses crypto package vulnerable to panic from malformed X.509 certificate

Affected range

SEMVER: introduced 0; fixed 0.0.0-20200124225646-8b5121be2f68

Fixed versions: 0.0.0-20200124225646-8b5121be2f68

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Affected range

SEMVER: introduced 0.1.0; fixed 0.17.0SEMVER: introduced 0; fixed 0.0.0-20231218163308-9d2ee975ef9fSEMVER: introduced 0; fixed 0.17.0

Fixed versions: 0.17.0, 0.0.0-20231218163308-9d2ee975ef9f

Show 7 more advisories
GHSA-r5c5-pr8j-pfp7 golang.org/x/crypto/salsa20/salsa uses insufficiently random values
GO-2026-6355 Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
GO-2026-6354 Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
GO-2024-2961 Limited directory traversal vulnerability on Windows in golang.org/x/crypto
GO-2025-4116 Potential denial of service in golang.org/x/crypto/ssh/agent