StackRadar

GO-2026-5932

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,267
of 17,828 indexed, latest versions
Container images
3,644
deployed by those charts
Fix available
None
affected package

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

Carried by container images the latest versions of 3,267 of 17,828 indexed charts deploy, on 3,644 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+160 moreno fix listed3,644
OSV records
GO-2026-5932

Charts affected

3,267 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,644 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/crypto@v0.27.0
no fix listed
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/crypto@v0.37.0
no fix listed
1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
golang.org/x/crypto@v0.25.0
no fix listed
1
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
golang.org/x/crypto@v0.38.0
no fix listed
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
golang.org/x/crypto@v0.14.0
no fix listed
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
no fix listed
1
bitnamilegacy/mongodb:7.0.5-debian-11-r66fe59ed5d79f
golang.org/x/crypto@v0.14.0
no fix listed
1
bitnamilegacy/mongodb:latestb0652af9c8d0
golang.org/x/crypto@v0.38.0
no fix listed
1
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
golang.org/x/crypto@v0.0.0-20190530122614-20be4c3c3ed5
no fix listed
1
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
no fix listed
1
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
no fix listed
1
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/crypto@v0.14.0
no fix listed
1
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
no fix listed
1
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
golang.org/x/crypto@v0.41.0
no fix listed
1
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/crypto@v0.32.0
no fix listed
1
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/crypto@v0.14.0
no fix listed
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/crypto@v0.25.0
no fix listed
1
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
no fix listed
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
no fix listed
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
golang.org/x/crypto@v0.37.0
no fix listed
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/crypto@v0.28.0
no fix listed
1
bitnami/mongodb:latest11ece5ac9685
golang.org/x/crypto@v0.54.0
no fix listed
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
golang.org/x/crypto@v0.35.0
no fix listed
1
bitnami/mongodb-exporter:latestf7034c13af4e
golang.org/x/crypto@v0.54.0
no fix listed
1
bitnami/redis-exporter:latestd5e1b663341d
golang.org/x/crypto@v0.56.0
no fix listed
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
no fix listed
1
bitnami/sealed-secrets-controller:0.37.03fe0103896b8
golang.org/x/crypto@v0.51.0
no fix listed
1
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/crypto@v0.41.0
no fix listed
1
blipai/deckard:0.0.28737d5d19a312
golang.org/x/crypto@v0.17.0
no fix listed
1
blipai/deckard:0.1.8db8cd873d0eb
golang.org/x/crypto@v0.53.0
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/crypto@v0.32.0
no fix listed
1
bluenviron/mediamtx:latest-ffmpeg9d148b5f2990
golang.org/x/crypto@v0.55.0
no fix listed
1
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/crypto@v0.49.0
no fix listed
1
bolkedebruin/rdpgw:masterc0dc0589373a
golang.org/x/crypto@v0.46.0
no fix listed
1
breton/cool:dev41b1bb483aa2
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
no fix listed
1
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
no fix listed
1
buddyspencer/gickup:0.10.386b656f19b0c1
golang.org/x/crypto@v0.36.0
no fix listed
1
buddyspencer/gickup:0.10.309e7dbf923c12
golang.org/x/crypto@v0.22.0
no fix listed
1
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
no fix listed
1
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/crypto@v0.9.0
no fix listed
1
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/crypto@v0.28.0
no fix listed
1
bytebase/bytebase:latesta6d845773b60
golang.org/x/crypto@v0.54.0
no fix listed
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/crypto@v0.9.0
no fix listed
1
caarlos0/domain_exporter:v1.23.0d11dec138900
golang.org/x/crypto@v0.18.0
no fix listed
1
calico/cni:v3.28.0cef0c907b8f4
golang.org/x/crypto@v0.22.0
no fix listed
1
calico/cni:v3.28.1e486870cfde8
golang.org/x/crypto@v0.22.0
no fix listed
1
calico/kube-controllers:v3.28.08f04e4772a2b
golang.org/x/crypto@v0.22.0
no fix listed
1
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/crypto@v0.22.0
no fix listed
1
calico/node:v3.28.0385bf6391fea
golang.org/x/crypto@v0.22.0
no fix listed
1
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/crypto@v0.22.0
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.