StackRadar

GO-2026-5932

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,265
of 17,828 indexed, latest versions
Container images
3,640
deployed by those charts
Fix available
None
affected package

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

Carried by container images the latest versions of 3,265 of 17,828 indexed charts deploy, on 3,640 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+160 moreno fix listed3,640
OSV records
GO-2026-5932

Charts affected

3,265 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,640 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/peak-scale/observability-tenancy/loki-proxy:0.4.1548e962d0061
golang.org/x/crypto@v0.41.0
no fix listed
1
ghcr.io/peak-scale/sops-operator:0.10.11da9b716b792
golang.org/x/crypto@v0.54.0
no fix listed
1
ghcr.io/performancecopilot/archive-analysis:latestba9f5a44ad68
golang.org/x/crypto@v0.17.0
no fix listed
1
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
golang.org/x/crypto@v0.24.0
no fix listed
1
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
no fix listed
1
ghcr.io/platform-mesh/platform-mesh/kubernetes-graphql-gateway:v1.20.02e6c9c111893
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/platform-mesh/platform-mesh/security-operator:v0.36.09b26032812fd
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/platform-mesh/platform-mesh/virtual-workspaces:v0.17.0bb2ee6241719
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/pocket-id/pocket-id:v2.14.001540977dcf4
golang.org/x/crypto@v0.54.0
no fix listed
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
golang.org/x/crypto@v0.50.0
no fix listed
1
ghcr.io/poweradmin/cert-manager-webhook-poweradmin:v0.2.14163f4e51bebb
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
golang.org/x/crypto@v0.31.0
no fix listed
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
golang.org/x/crypto@v0.16.0
no fix listed
1
ghcr.io/prophetse7en/clonarr:latest9400d298b37a
golang.org/x/crypto@v0.53.0
no fix listed
1
ghcr.io/pschichtel/cert-manager-webhook-cloudns:1.1.01020638bbe23
golang.org/x/crypto@v0.18.0
no fix listed
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
golang.org/x/crypto@v0.52.0
no fix listed
1
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
golang.org/x/crypto@v0.51.0
no fix listed
1
ghcr.io/pulumi/pulumi-esc-csi-provider:0.1.13fb058e93502
golang.org/x/crypto@v0.31.0
no fix listed
1
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
golang.org/x/crypto@v0.51.0
no fix listed
1
ghcr.io/quenchworks/images/alertmanagerd1e7285865d8
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/argocd269dd63572dc
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/argo-workflows21ee2a679f59
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/autheliab1b927f8e16c
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/blackbox-exporter9db9c60495cf
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/caddy8e89a25b3251
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/cadenceea676e4999bc
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/centrifugo5312d9af2d03
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/cert-manager-cainjector7df29eb359f0
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/cert-manager-controller6b5c41a86c2f
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/cert-manager-webhookdcbad2006021
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/chartmuseumd5ee9e8861c6
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/coolify-app92ab37c5b6c4
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/corednsae89f8827b25
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/coroot4744f3de113a
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/crossplane69a727135d8c
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/descheduler6c8ec6a628c4
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/dex8b41a7c5f1bf
golang.org/x/crypto@v0.55.0
no fix listed
1
ghcr.io/quenchworks/images/distributiond6a9b6be2cad
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/envoy-gateway006399c56f3f
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/etcd05765ee83074
golang.org/x/crypto@v0.55.0
no fix listed
1
ghcr.io/quenchworks/images/etcd5ee569c55982
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/external-dns39be2f335319
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/external-secretsc8b275ec944c
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/filebrowser3d569c74b238
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/forgejod3af0a1be62a
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/gitea5dd27e37a92d
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/gotifye25e0fcfddae
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/harbor-corefdd355a617e2
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/harbor-registryfd8d3f9a59fa
golang.org/x/crypto@v0.57.0
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.