StackRadar

CVE-2025-58181

Medium

Advisory

Published 19 Nov 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,051
of 17,803 indexed, latest versions
Container images
2,349
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

Carried by container images the latest versions of 2,051 of 17,803 indexed charts deploy, on 2,349 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+146 more0.45.02,349
OSV records
GHSA-j5w8-q4qc-rx2x
Also known as
GO-2025-4134

Charts affected

2,051 by stars
ChartLatestAffected imagesRadar Score
zahori-moonzahoriVerified publisher1.0.11 of 3See more

zahori-moon zahori 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-58181.

Container imageDigestPackageFixed in
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/crypto@v0.10.0
0.45.0

Open the chart page →

2,908

Container images carrying it

2,349 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.45.0
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/crypto@v0.16.0
0.45.0
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.45.0
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
golang.org/x/crypto@v0.35.0
0.45.0
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/crypto@v0.17.0
0.45.0
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.45.0
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/crypto@v0.6.0
0.45.0
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
golang.org/x/crypto@v0.18.0
0.45.0
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/crypto@v0.0.0-20220208050332-20e1d8d225ab
0.45.0
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
ghcr.io/ferretdb/ferretdb:2.7.05706414241eb
golang.org/x/crypto@v0.43.0
0.45.0
1
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
golang.org/x/crypto@v0.7.0
0.45.0
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/crypto@v0.41.0
0.45.0
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/crypto@v0.42.0
0.45.0
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/crypto@v0.26.0
0.45.0
1
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/crypto@v0.33.0
0.45.0
1
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/crypto@v0.32.0
0.45.0
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/crypto@v0.32.0
0.45.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.45.0
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/crypto@v0.4.0
0.45.0
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/crypto@v0.40.0
0.45.0
1
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/crypto@v0.32.0
0.45.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/crypto@v0.14.0
0.45.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/crypto@v0.14.0
0.45.0
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.45.0
1
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
golang.org/x/crypto@v0.33.0
0.45.0
1
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
golang.org/x/crypto@v0.31.0
0.45.0
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
golang.org/x/crypto@v0.6.0
0.45.0
1
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
golang.org/x/crypto@v0.19.0
0.45.0
1
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
golang.org/x/crypto@v0.36.0
0.45.0
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/crypto@v0.14.0
0.45.0
1
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
golang.org/x/crypto@v0.36.0
0.45.0
1
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
golang.org/x/crypto@v0.41.0
0.45.0
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
golang.org/x/crypto@v0.42.0
0.45.0
1
ghcr.io/glauth/glauth:v2.5.209c782ca5984
golang.org/x/crypto@v0.18.0
0.45.0
1
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
golang.org/x/crypto@v0.36.0
0.45.0
1
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
golang.org/x/crypto@v0.29.0
0.45.0
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/crypto@v0.39.0
0.45.0
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
golang.org/x/crypto@v0.43.0
0.45.0
1
ghcr.io/grafana/grafana-operator:v5.18.00af2faec9d6f
golang.org/x/crypto@v0.36.0
0.45.0
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
golang.org/x/crypto@v0.40.0
0.45.0
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/crypto@v0.9.0
0.45.0
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.45.0
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.45.0
1
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
golang.org/x/crypto@v0.36.0
0.45.0
1
ghcr.io/helmfile/helmfile:v1.7.4f20e612d5a98
golang.org/x/crypto@v0.24.0
0.45.0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
golang.org/x/crypto@v0.26.0
0.45.0
1
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
golang.org/x/crypto@v0.26.0
0.45.0
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
golang.org/x/crypto@v0.26.0
0.45.0
1
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
golang.org/x/crypto@v0.26.0
0.45.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.