CVE-2026-46595
CriticalAdvisory
Published 22 May 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 10.0
- base score, highest
- EPSS
- 0.005
- 42nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,492
- of 17,821 indexed, latest versions
- Container images
- 2,818
- deployed by those charts
- Fix available
- 1 of 1
- affected package
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
Carried by container images the latest versions of 2,492 of 17,821 indexed charts deploy, on 2,818 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+154 more | 0.52.0 | 2,818 |
- OSV records
- GHSA-x527-x647-q7gg
- Also known as
- GO-2026-5023
Charts affected
2,492 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
2,818 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ubercadence/ | 2ac5491d13bb | golang.org/ | 0.52.0 | 2 |
| uselagoon/ | 2c89ed939b8b | golang.org/ | 0.52.0 | 2 |
| voltha/ | d6d79c08350a | golang.org/ | 0.52.0 | 2 |
| voltha/ | d8f2eb5f2a7e | golang.org/ | 0.52.0 | 2 |
| voltha/ | 7a325316fe59 | golang.org/ | 0.52.0 | 2 |
| weblate/ | 69c160d37a3c | golang.org/ | 0.52.0 | 2 |
| wener/ | cc9fd4da44c0 | golang.org/ | 0.52.0 | 2 |
| wener/ | 5c92cc9e8597 | golang.org/ | 0.52.0 | 2 |
| xelalex/ | 574054e1c417 | golang.org/ | 0.52.0 | 2 |
| zhenghaoz/ | 033046b432ec | golang.org/ | 0.52.0 | 2 |
| zhenghaoz/ | 39c565685b01 | golang.org/ | 0.52.0 | 2 |
| zhenghaoz/ | f7739f64c9b0 | golang.org/ | 0.52.0 | 2 |
| gcr.io/ | 2de1d15fc1f2 | golang.org/ | 0.52.0 | 2 |
| gcr.io/ | 5b93308a392c | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | bce133f3f511 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 77c9d29080eb | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 789692ab9193 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 0df4ae70e3bd | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | f6e481386d70 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 4249e403225a | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 1b530cf7c07f | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 82d0b161161d | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 2659f4c2ebb7 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 4768ea1c5fd2 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 38bfdf5e3774 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 78dc63bc5b89 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | b5210df46c05 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | f115777d1112 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | cf4428a3c79e | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 5e88f2205de1 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | e70364e88629 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | cd264d33efd4 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 678ba6833297 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 7d576be7f838 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | dc48471c7cf8 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | fba6fb872281 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | b940cab56435 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | e2abb798f29f | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 96f42450c5b1 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 0d1df8f436f7 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 7f59f7c08d1a | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 47cffbc65700 | golang.org/ | 0.52.0 | 2 |
| ghcr.io/ | 0e7bc9d34e86 | golang.org/ | 0.52.0 | 2 |
| public.ecr.aws/ | d47f43484055 | golang.org/ | 0.52.0 | 2 |
| public.ecr.aws/ | 8f9c32b866b0 | golang.org/ | 0.52.0 | 2 |
| public.ecr.aws/ | 364b3ff0fcb7 | golang.org/ | 0.52.0 | 2 |
| public.ecr.aws/ | 2d28f9e3eab4 | golang.org/ | 0.52.0 | 2 |
| public.ecr.aws/ | 301216788e93 | golang.org/ | 0.52.0 | 2 |
| public.ecr.aws/ | fe9de719f91e | golang.org/ | 0.52.0 | 2 |
| public.ecr.aws/ | 26ac7263a823 | golang.org/ | 0.52.0 | 2 |