Information on source package golang-go.crypto

Available versions

ReleaseVersion
bookworm1:0.4.0-1
trixie1:0.25.0-1
forky1:0.56.0-1
sid1:0.56.0-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-78662vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedPreviously, a channel registered in the mux's chanList is not usable u ...
CVE-2026-56855vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedPreviously, after a channel has been established, a malicious peer cou ...
CVE-2026-56854vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedThe source-address critical option in the Permissions returned by an a ...
CVE-2026-46598vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedFor certain crafted inputs, a 'ed25519.PrivateKey' was created by cast ...
CVE-2026-46597vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAn incorrectly placed cast from bytes to int allowed for server-side p ...
CVE-2026-46595vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedPreviously, CVE-2024-45337 fixed an authorization bypass for misused s ...
CVE-2026-42508vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedPreviously, a revoked 'SignatureKey' belonging to a CA was not correct ...
CVE-2026-39835vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedSSH servers which use CertChecker as a public key callback without set ...
CVE-2026-39834vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedWhen writing data larger than 4GB in a single Write call on an SSH cha ...
CVE-2026-39833vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedThe in-memory keyring returned by NewKeyring() silently accepted keys ...
CVE-2026-39832vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedWhen adding a key to a remote agent constraint extensions such as rest ...
CVE-2026-39831vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedThe Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...
CVE-2026-39830vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedA malicious SSH peer could send unsolicited global request responses t ...
CVE-2026-39829vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedThe RSA and DSA public key parsers did not enforce size limits on key ...
CVE-2026-39828vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedWhen an SSH server authentication callback returned PartialSuccessErro ...
CVE-2026-39827vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAn authenticated SSH client that repeatedly opened channels which were ...
CVE-2025-58181vulnerable (no DSA)vulnerable (no DSA)fixedfixedSSH servers parsing GSSAPI authentication requests do not validate the ...
CVE-2025-47914vulnerable (no DSA)vulnerable (no DSA)fixedfixedSSH Agent servers do not validate the size of messages when processing ...
CVE-2025-47913vulnerable (no DSA)vulnerable (no DSA)fixedfixedSSH clients receiving SSH_AGENT_SUCCESS when expecting a typed respons ...
CVE-2025-22869vulnerable (no DSA)vulnerable (no DSA)fixedfixedSSH servers which implement file transfer protocols are vulnerable to ...
CVE-2024-45337vulnerable (no DSA)vulnerable (no DSA)fixedfixedApplications and libraries which misuse connection.serverAuthenticate ...
CVE-2023-48795vulnerable (no DSA)fixedfixedfixedThe SSH transport protocol with certain OpenSSH extensions, found in O ...

Resolved issues

BugDescription
CVE-2022-30636httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token ...
CVE-2022-27191The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1 ...
CVE-2021-43565The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of g ...
CVE-2020-29652A nil pointer dereference in the golang.org/x/crypto/ssh component thr ...
CVE-2020-9283golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go a ...
CVE-2019-11841A message-forgery issue was discovered in crypto/openpgp/clearsign/cle ...
CVE-2019-11840An issue was discovered in the supplementary Go cryptography library, ...
CVE-2017-3204The Go SSH library (x/crypto/ssh) by default does not verify host keys ...

Security announcements

DSA / DLADescription
DLA-3455-1golang-go.crypto - security update
DLA-2402-1golang-go.crypto - security update
DLA-1920-1golang-go.crypto - security update
DLA-1840-1golang-go.crypto - security update

Search for package or bug name: Reporting problems