golang.org/x/[email protected] has vulnerabilities — update to latest
Update to >= 0.0.0-20220525230936-793ad666bf5e to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2020-29652 | golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability | 0.0.0-20201216223049-8b5274cf687f |
| medium | CVE-2023-48795 | Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin | 0.0.0-20231218163308-9d2ee975ef9f |
| high | CVE-2022-27191 | golang.org/x/crypto/ssh Denial of service via crafted Signer | 0.0.0-20220314234659-1baeb1ce4c0b |
| high | BIT-golang-2020-7919 | Helm uses crypto package vulnerable to panic from malformed X.509 certificate | 0.0.0-20200124225646-8b5121be2f68 |
| high | CVE-2020-9283 | Improper Verification of Cryptographic Signature in golang.org/x/crypto | 0.0.0-20200220183623-bac4c82f6975 |
| high | CVE-2021-43565 | x/crypto/ssh vulnerable to panic via malformed packets | 0.0.0-20211202192323-5770296d904e |
| medium | CVE-2019-11840 | golang.org/x/crypto/salsa20/salsa uses insufficiently random values | 0.0.0-20190320223903-b7391e95e576 |
| medium | CVE-2019-11841 | Golang/x/crypto message forgery vulnerability | 0.0.0-20190424203555-c05e17bb3b2d |
| high | CVE-2017-3204 | golang.org/x/crypto/ssh Man-in-the-Middle attack | 0.0.0-20170330155735-e4e2799dd7aa |
| unknown | CVE-2020-9283 | Panic due to improper verification of cryptographic signatures in golang.org/x/crypto/ssh | 0.0.0-20200220183623-bac4c82f6975 |
| unknown | CVE-2017-3204 | Man-in-the-middle attack in golang.org/x/crypto/ssh | 0.0.0-20170330155735-e4e2799dd7aa |
| unknown | CVE-2020-29652 | Panic on crafted authentication request message in golang.org/x/crypto/ssh | 0.0.0-20201216223049-8b5274cf687f |
| unknown | CVE-2022-27191 | Denial of service via crafted Signer in golang.org/x/crypto/ssh | 0.0.0-20220314234659-1baeb1ce4c0b |
| unknown | CVE-2019-11840 | Insufficiently random values in golang.org/x/crypto/salsa20 | 0.0.0-20190320223903-b7391e95e576 |
| unknown | BIT-golang-2020-7919 | Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyte | 0.0.0-20200124225646-8b5121be2f68 |
| unknown | CVE-2021-43565 | Panic on malformed packets in golang.org/x/crypto/ssh | 0.0.0-20211202192323-5770296d904e |
| unknown | CVE-2019-11841 | Misleading message verification in golang.org/x/crypto/openpgp/clearsign | 0.0.0-20190424203555-c05e17bb3b2d |
| unknown | CVE-2022-30636 | Limited directory traversal vulnerability on Windows in golang.org/x/crypto | 0.0.0-20220525230936-793ad666bf5e |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/golang.org/x/cryptoLast updated · 2026-04-09T15:33:22Z