StackRadar

CVE-2025-58181

Medium

Advisory

Published 19 Nov 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,054
of 17,790 indexed, latest versions
Container images
2,352
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

Carried by container images the latest versions of 2,054 of 17,790 indexed charts deploy, on 2,352 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+146 more0.45.02,352
OSV records
GHSA-j5w8-q4qc-rx2x
Also known as
GO-2025-4134

Charts affected

2,054 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2025-58181.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.45.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.45.0

Open the chart page →

7,998
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-58181.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0

Open the chart page →

3,024
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-58181.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.45.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.45.0

Open the chart page →

5,047
zahori-moonzahoriVerified publisher1.0.11 of 3See more

zahori-moon zahori 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-58181.

Container imageDigestPackageFixed in
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/crypto@v0.10.0
0.45.0

Open the chart page →

2,907

Container images carrying it

2,352 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/crypto@v0.9.0
0.45.0
1
erigontech/erigon:v2.61.288706754b627
golang.org/x/crypto@v0.31.0
0.45.0
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
ethereum/client-go:v1.15.101f36ca5922a5
golang.org/x/crypto@v0.35.0
0.45.0
1
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/crypto@v0.36.0
0.45.0
1
ethereum/client-go:v1.10.186d6d12a40465
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.45.0
1
ethereum/client-go:v1.14.8886ec69b35b0
golang.org/x/crypto@v0.22.0
0.45.0
1
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.45.0
1
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.45.0
1
ethereumoptimism/l2geth:0.5.315577036dc36d
golang.org/x/crypto@v0.0.0-20220307211146-efcb8507fb70
0.45.0
1
ethersphere/bee:2.2.0a884fd84b72f
golang.org/x/crypto@v0.23.0
0.45.0
1
ethersphere/onboarding-faucet:0.3.0513154aab230
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.45.0
1
ethpandaops/armiarma:master1a9c3264f0a9
golang.org/x/crypto@v0.21.0
0.45.0
1
ethpandaops/blob-me-baby:latestad26158420dd
golang.org/x/crypto@v0.14.0
0.45.0
1
ethpandaops/dugtrio:1.0.0e261d1734e9f
golang.org/x/crypto@v0.10.0
0.45.0
1
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
ethpandaops/execution-processor:latest5c4832e9588f
golang.org/x/crypto@v0.43.0
0.45.0
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
golang.org/x/crypto@v0.41.0
0.45.0
1
ethpandaops/service-authenticatoor:main27b8e5ea3125
golang.org/x/crypto@v0.37.0
0.45.0
1
ethpandaops/splitoor:latest989da6bea4bd
golang.org/x/crypto@v0.36.0
0.45.0
1
everpcpc/channels:latestb378d137ae8b
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.45.0
1
factly/dega-api:0.15.166fafc7b0a17
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
factly/dega-server:0.15.194d21479382e
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
factly/mande-server:0.34.1384d384310ef
golang.org/x/crypto@v0.1.0
0.45.0
1
factly/vidcheck-server:0.12.087064eb0463c
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
falcosecurity/falcosidekick:2.32.01976da721518
golang.org/x/crypto@v0.41.0
0.45.0
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.45.0
1
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
golang.org/x/crypto@v0.22.0
0.45.0
1
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.45.0
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.45.0
1
fission/fission-bundle:1.14.13fcfd8a0fa5d
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.45.0
1
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.45.0
1
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/crypto@v0.9.0
0.45.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
golang.org/x/crypto@v0.37.0
0.45.0
1
flashbots/mev-boost:1.8.07c486b5789da
golang.org/x/crypto@v0.23.0
0.45.0
1
fleetdm/fleet:v4.66.012e644b7f40e
golang.org/x/crypto@v0.35.0
0.45.0
1
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/crypto@v0.9.0
0.45.0
1
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/crypto@v0.9.0
0.45.0
1
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
golang.org/x/crypto@v0.5.0
0.45.0
1
flomesh/osm-edge-controller:1.3.9add7a4da4622
golang.org/x/crypto@v0.5.0
0.45.0
1
flomesh/osm-edge-injector:1.3.947287e3ad324
golang.org/x/crypto@v0.5.0
0.45.0
1
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.45.0
1
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.45.0
1
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/crypto@v0.17.0
0.45.0
1
foxcpp/maddy:0.7.16ab538e2f28b
golang.org/x/crypto@v0.18.0
0.45.0
1
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.45.0
1
foxcpp/maddy:0.9.2a4b839985b9b
golang.org/x/crypto@v0.32.0
0.45.0
1
foxcpp/maddy:0.8.2eeb5813fc4d1
golang.org/x/crypto@v0.32.0
0.45.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.45.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.