StackRadar

GO-2026-5932

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,265
of 17,828 indexed, latest versions
Container images
3,640
deployed by those charts
Fix available
None
affected package

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

Carried by container images the latest versions of 3,265 of 17,828 indexed charts deploy, on 3,640 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+160 moreno fix listed3,640
OSV records
GO-2026-5932

Charts affected

3,265 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,640 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aquasec/trivy:0.32.0973d0df16189
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
no fix listed
1
aquasec/trivy:0.69.3bcc376de8d77
golang.org/x/crypto@v0.46.0
no fix listed
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
golang.org/x/crypto@v0.32.0
no fix listed
1
arigaio/atlas-operator:0.7.111c4caa13c92b
golang.org/x/crypto@v0.39.0
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
no fix listed
1
artifacthub/db-migrator:v1.23.028c13565ac5c
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
no fix listed
1
artifacthub/db-migrator:v1.19.02a746b289fcd
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/crypto@v0.24.0
no fix listed
1
artifacthub/hub:v1.23.07d3a91c539dc
golang.org/x/crypto@v0.53.0
no fix listed
1
artifacthub/scanner:v1.23.02d8365601f0e
golang.org/x/crypto@v0.53.0
no fix listed
1
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/crypto@v0.24.0
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
golang.org/x/crypto@v0.42.0
no fix listed
1
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/crypto@v0.24.0
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/crypto@v0.22.0
no fix listed
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
no fix listed
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
no fix listed
1
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/crypto@v0.28.0
no fix listed
1
authelia/authelia:4.39.2616b804fbf670
golang.org/x/crypto@v0.57.0
no fix listed
1
authzed/spicedb:latestaa96009a0477
golang.org/x/crypto@v0.56.0
no fix listed
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/crypto@v0.22.0
no fix listed
1
axllent/mailpit:v1.31.198b916bd3c8d
golang.org/x/crypto@v0.56.0
no fix listed
1
axllent/mailpit:v1.31.0c96991d9bef7
golang.org/x/crypto@v0.55.0
no fix listed
1
b3log/siyuan:v3.8.36ab17ed3ca40
golang.org/x/crypto@v0.55.0
no fix listed
1
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/crypto@v0.36.0
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/crypto@v0.14.0
no fix listed
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
no fix listed
1
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/crypto@v0.36.0
no fix listed
1
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/crypto@v0.13.0
no fix listed
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/crypto@v0.0.0-20220314234659-1baeb1ce4c0b
no fix listed
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
no fix listed
1
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/crypto@v0.3.0
no fix listed
1
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
no fix listed
1
binrc/headcni:1.0.10e199c334b957
golang.org/x/crypto@v0.50.0
no fix listed
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
golang.org/x/crypto@v0.23.0
no fix listed
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/crypto@v0.10.0
no fix listed
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/crypto@v0.41.0
no fix listed
1
bitnamilegacy/git:latest4b08d0c5af8d
golang.org/x/crypto@v0.36.0
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/crypto@v0.27.0
no fix listed
1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
no fix listed
1
bitnamilegacy/kube-state-metrics:204a3044b384b
golang.org/x/crypto@v0.38.0
no fix listed
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
golang.org/x/crypto@v0.17.0
no fix listed
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/crypto@v0.3.0
no fix listed
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/crypto@v0.24.0
no fix listed
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/crypto@v0.17.0
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
golang.org/x/crypto@v0.40.0
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
golang.org/x/crypto@v0.37.0
no fix listed
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
golang.org/x/crypto@v0.23.0
no fix listed
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
golang.org/x/crypto@v0.36.0
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/crypto@v0.27.0
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/crypto@v0.27.0
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.