StackRadar

GO-2026-5932

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,265
of 17,828 indexed, latest versions
Container images
3,640
deployed by those charts
Fix available
None
affected package

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

Carried by container images the latest versions of 3,265 of 17,828 indexed charts deploy, on 3,640 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+160 moreno fix listed3,640
OSV records
GO-2026-5932

Charts affected

3,265 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,640 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/quenchworks/images/velerofd3b23ef772f
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/vikunja00830bc0634d
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/weaviateea0b54479ff1
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/woodpecker1a8098ec2aaf
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/zitadel68cf8a1d6172
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/quenchworks/images/zotd92ffb518563
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
golang.org/x/crypto@v0.13.0
no fix listed
1
ghcr.io/rafpe/kube-oidc-proxy:1.8.1300f51feb1a7
golang.org/x/crypto@v0.55.0
no fix listed
1
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/riotkit-org/backup-maker-controller:v0.1.262370545ba3d
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
no fix listed
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
no fix listed
1
ghcr.io/riotkit-org/waf-proxy:snapshot683656fdace2
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
no fix listed
1
ghcr.io/riverqueue/riverui:0.5.32dc54179b25a
golang.org/x/crypto@v0.22.0
no fix listed
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
golang.org/x/crypto@v0.45.0
no fix listed
1
ghcr.io/runnerm/simply-dns-webhook:v1.10.0fdfffa3984a5
golang.org/x/crypto@v0.49.0
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
golang.org/x/crypto@v0.52.0
no fix listed
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
golang.org/x/crypto@v0.40.0
no fix listed
1
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
no fix listed
1
ghcr.io/schmitzis/cert-manager-webhook-bunny:latest125e31c8e85a
golang.org/x/crypto@v0.5.0
no fix listed
1
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
no fix listed
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
golang.org/x/crypto@v0.38.0
no fix listed
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
golang.org/x/crypto@v0.37.0
no fix listed
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
golang.org/x/crypto@v0.39.0
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
golang.org/x/crypto@v0.45.0
no fix listed
1
ghcr.io/sergelogvinov/proxmox-cloud-controller-manager:v0.15.0fbc553921145
golang.org/x/crypto@v0.54.0
no fix listed
1
ghcr.io/sergelogvinov/tailscale:1.102.3d91287e83d1a
golang.org/x/crypto@v0.54.0
no fix listed
1
ghcr.io/sergeyslonimsky/elara:0.4.050fb24449dc3
golang.org/x/crypto@v0.53.0
no fix listed
1
ghcr.io/shaharia-lab/teredix:0.0.2ec727be4417a
golang.org/x/crypto@v0.17.0
no fix listed
1
ghcr.io/shini4i/argo-watcher:v1.4.13a9a4ab9d839
golang.org/x/crypto@v0.56.0
no fix listed
1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
golang.org/x/crypto@v0.48.0
no fix listed
1
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
golang.org/x/crypto@v0.50.0
no fix listed
1
ghcr.io/siderolabs/talos-backup:v0.1.0-beta.203a71e140f1d
golang.org/x/crypto@v0.24.0
no fix listed
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
golang.org/x/crypto@v0.37.0
no fix listed
1
ghcr.io/sigstore/rekor-tiles/gcp:v2.2.1e401cfe033c9
golang.org/x/crypto@v0.51.0
no fix listed
1
ghcr.io/sigstore/scaffolding/serverae8eb69c7b70
golang.org/x/crypto@v0.43.0
no fix listed
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
golang.org/x/crypto@v0.52.0
no fix listed
1
ghcr.io/sigstore/timestamp-server:v2.1.08637f0482ed1
golang.org/x/crypto@v0.51.0
no fix listed
1
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/crypto@v0.24.0
no fix listed
1
ghcr.io/skyhook-io/radar:1.14.18fda6d4c3e80
golang.org/x/crypto@v0.57.0
no fix listed
1
ghcr.io/slinkyproject/slurm-bridge-scheduler:1.2.2d0eec33ab53e
golang.org/x/crypto@v0.55.0
no fix listed
1
ghcr.io/slinkyproject/slurm-operator:1.2.20ce1930f20de
golang.org/x/crypto@v0.55.0
no fix listed
1
ghcr.io/spegel-org/spegel26c60b05e08a
golang.org/x/crypto@v0.53.0
no fix listed
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
golang.org/x/crypto@v0.6.0
no fix listed
1
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
golang.org/x/crypto@v0.6.0
no fix listed
1
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
golang.org/x/crypto@v0.6.0
no fix listed
1
ghcr.io/stacklok/toolhive/operator:v0.50.07998095e6b99
golang.org/x/crypto@v0.57.0
no fix listed
1
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/crypto@v0.45.0
no fix listed
1
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/crypto@v0.24.0
no fix listed
1
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/crypto@v0.37.0
no fix listed
1
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/crypto@v0.13.0
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.