Crypto
41 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Crypto, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Crypto CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 1 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 3 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 13 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 2 |
Severity
How the 41 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical9
- High17
- Medium15
Latest CVEs
The 15 most recently published vulnerabilities affecting Crypto.
- CVE-2026-78662Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh7.5
- CVE-2026-56855Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh7.5
- CVE-2026-42508Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts9.1
- CVE-2026-46595Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh10.0
- CVE-2026-46598Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent5.3
- CVE-2026-39834Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh9.1
- CVE-2026-39829Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh7.5
- CVE-2026-39827Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh6.5
- CVE-2026-39830Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh9.1
- CVE-2026-39831Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh9.1
- CVE-2026-46597Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh7.5
- CVE-2026-39828Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh6.3
- CVE-2026-39835Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh5.3
- CVE-2026-39833Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent9.1
- CVE-2026-39832Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent9.1
Product grouping is registry-driven, with AI assist and human review. How it works