StackRadar

GO-2026-5932

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,265
of 17,828 indexed, latest versions
Container images
3,640
deployed by those charts
Fix available
None
affected package

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

Carried by container images the latest versions of 3,265 of 17,828 indexed charts deploy, on 3,640 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+160 moreno fix listed3,640
OSV records
GO-2026-5932

Charts affected

3,265 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,640 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
alpine/k8s:1.35.6b7a12c5ddf26
golang.org/x/crypto@v0.51.0
no fix listed
1
alpine/k8s:1.30.0bd01dae02676
golang.org/x/crypto@v0.17.0
no fix listed
1
alpine/k8s:1.30.2cd560fce90f7
golang.org/x/crypto@v0.24.0
no fix listed
1
alpine/k8s:1.35.5d870622d0040
golang.org/x/crypto@v0.50.0
no fix listed
1
alpine/k8s:1.28.13e5c0b053fed7
golang.org/x/crypto@v0.24.0
no fix listed
1
alpine/k8s:1.32.3eec354133193
golang.org/x/crypto@v0.32.0
no fix listed
1
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/crypto@v0.13.0
no fix listed
1
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
no fix listed
1
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
no fix listed
1
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
golang.org/x/crypto@v0.1.0
no fix listed
1
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/crypto@v0.14.0
no fix listed
1
amazon/cloudwatch-agent:latest-arm649dea6643715a
golang.org/x/crypto@v0.53.0
no fix listed
1
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
no fix listed
1
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
golang.org/x/crypto@v0.10.0
no fix listed
1
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
golang.org/x/crypto@v0.10.0
no fix listed
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
no fix listed
1
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
no fix listed
1
anchore/kubernetes-admission-controller:v0.8.51a1a374658c8
golang.org/x/crypto@v0.56.0
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/crypto@v0.36.0
no fix listed
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/crypto@v0.0.0-20220307211146-efcb8507fb70
no fix listed
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/crypto@v0.0.0-20191202143827-86a70503ff7e
no fix listed
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
no fix listed
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
golang.org/x/crypto@v0.55.0
no fix listed
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
golang.org/x/crypto@v0.55.0
no fix listed
1
antrea/antrea-ui-backend:v0.8.019f3c0113330
golang.org/x/crypto@v0.57.0
no fix listed
1
antrea/flow-aggregator:v2.7.0065193e7572f
golang.org/x/crypto@v0.55.0
no fix listed
1
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/crypto@v0.53.0
no fix listed
1
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
no fix listed
1
apache/camel-k:2.11.0d173e7efe258
golang.org/x/crypto@v0.54.0
no fix listed
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/crypto@v0.6.0
no fix listed
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
no fix listed
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/crypto@v0.0.0-20191122220453-ac88ee75c92c
no fix listed
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
no fix listed
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/crypto@v0.0.0-20191122220453-ac88ee75c92c
no fix listed
1
apache/yunikorn:scheduler-1.9.096832082e9cf
golang.org/x/crypto@v0.52.0
no fix listed
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
golang.org/x/crypto@v0.26.0
no fix listed
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/crypto@v0.17.0
no fix listed
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/crypto@v0.13.0
no fix listed
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/crypto@v0.1.0
no fix listed
1
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/crypto@v0.38.0
no fix listed
1
appwrite/appwrite:2.2.0896bdd024de3
golang.org/x/crypto@v0.48.0
no fix listed
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/crypto@v0.22.0
no fix listed
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
no fix listed
1
aquasec/kube-bench:v0.6.176672264accce
golang.org/x/crypto@v0.4.0
no fix listed
1
aquasec/kube-bench:v0.15.07a8fa32dce21
golang.org/x/crypto@v0.45.0
no fix listed
1
aquasec/kube-bench:v0.6.9c329d73fea58
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
no fix listed
1
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
no fix listed
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
no fix listed
1
aquasec/tracee:0.24.1cfbbfee972e6
golang.org/x/crypto@v0.40.0
no fix listed
1
aquasec/trivy:0.43.1944a04445179
golang.org/x/crypto@v0.10.0
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.