CVE-2026-46597
HighAdvisory
Published 22 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 40th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,451
- of 17,805 indexed, latest versions
- Container images
- 2,774
- deployed by those charts
- Fix available
- 1 of 1
- affected package
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
Carried by container images the latest versions of 2,451 of 17,805 indexed charts deploy, on 2,774 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+153 more | 0.52.0 | 2,774 |
- OSV records
- GHSA-q4h4-gmj2-qvw2
- Also known as
- GO-2026-5013
Charts affected
2,451 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zahori-moonzahoriVerified publisher | 1.0.1 | 1 of 3See more | 2,908 |
Container images carrying it
2,774 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 744bc929a579 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 2f06e72cef36 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | b8e03da90e70 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 21de3771fdd5 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | e5f5c254a55a | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | c62c89ee706d | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | f5c797f7fbe7 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | b1557553a2b3 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 7465f35b684c | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 45554a03e448 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | dc6b5fdcec06 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | dfbef0285e14 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 0efd9d9ef6ca | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | ab213b156017 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 81f6007abb4e | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 6ec488d89b56 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | b1857871e06c | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | b58345fe8209 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 36ce246d884e | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | f9104080d9a7 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 67d18880448c | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 6b99ee9feece | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 7de54b6dedc8 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | d8cc6ffb9819 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | d6c2532ea386 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | e4b66308d8f6 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 913f0858eb24 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | a96e06ec5e9f | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 16907aae5de1 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 79c9c76a78e6 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 9cb4acb742a9 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | cdbbed831f28 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | a608b798fda5 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 345174727a2b | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 657a2c9f6e6d | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 4c708ecf7dc4 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | f80349eb018b | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 5cf1e5709820 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 3490d9900af1 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | c8af1c5aae40 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | a06c8ebef427 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | bf3cb9b505b6 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | d4022cd32df5 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 10b7945d4f09 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 752f1aa02438 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | a354b8dc7e6a | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | b3d6600c8ba5 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 32b6a174b419 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | 13dcbc7ebfc6 | golang.org/ | 0.52.0 | 1 |
| ghcr.io/ | e341aefa9a90 | golang.org/ | 0.52.0 | 1 |