An open index of dependabot pull requests across open source projects.

golang.org/x/crypto

Ecosystem:
go
Package URL:
pkg:golang/golang.org/x/crypto
Total PRs:
10,704 Dependabot PRs
Latest PR:
about 4 hours ago
Unique Repositories:
5,077 repositories
Unique Repos (30 days):
150 repositories
Security Advisories
Golang/x/crypto message forgery vulnerability
GHSA-x3jr-pf6g-c48f CVE-2019-11841 MODERATE published over 3 years ago • updated 5 months ago
A message-forgery issue was discovered in `crypto/openpgp/clearsign/clearsign.go` in supplementary Go cryptography libraries 2019-03-25. According ...
x/crypto/ssh vulnerable to panic via malformed packets
GHSA-gwc9-m7rh-j2ww CVE-2021-43565 HIGH published about 3 years ago • updated 4 months ago
The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an unauthenticated attacker to panic an SSH server....
golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
GHSA-3vm4-22fp-5rfm CVE-2020-29652 HIGH published over 3 years ago • updated 3 months ago
A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cau...
golang.org/x/crypto/ssh Man-in-the-Middle attack
GHSA-xhjq-w7xm-p8qj CVE-2017-3204 HIGH published over 2 years ago • updated 3 months ago
The Go SSH library (golang.org/x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks if ClientConfig.HostKeyCa...
golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange
GHSA-hcg3-q754-cr77 CVE-2025-22869 HIGH published 7 months ago • updated 3 months ago
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowl...
Recent PRs
Package Details
Name: golang.org/x/crypto
Ecosystem: go
PURL Type: golang
Package URL: pkg:golang/golang.org/x/crypto
JSON API: View JSON
Security Advisories

11

Active advisories
CRITICAL 1
HIGH 7
MODERATE 3
View All golang Advisories
Package Information
Description:

Homepage: https://cs.opensource.google/go/x/crypto
Latest Release: v0.39.0
5 months ago
Dependent Repos: 269,003
Dependent Packages: 125,672
Ranking: Top 0.0007% by dependent repos Top 0.0002% by dependent pkgs
PR Status
Open 4,472 (41.8%)
Merged 2,241 (20.9%)
Closed 2,705 (25.3%)
PR Types
Minor 9,382 (87.6%)