[security][CVE-2026-39832] golang.org/x/crypto in nats runtime image #147

Open
opened 2026-07-16 13:21:10 +00:00 by dirtydishes · 0 comments
Owner

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface.

  • CVE: CVE-2026-39832
  • Affected component: golang.org/x/crypto in nats runtime image
  • Severity: HIGH
  • In-repo version(s): golang.org/x/crypto v0.37.0 in nats-server (nats:2.10)
  • Project impact: The shipped NATS runtime binary embeds a vulnerable x/crypto release, so affected SSH authentication callback handling remains exposed until the runtime image is refreshed.
  • Remediation: Upgrade to a NATS image built with golang.org/x/crypto 0.52.0 or newer.

Counters for this run:

  • unaddressed critical CVEs: 6
  • unaddressed medium/low CVEs: 119
  • unaddressed total CVEs: 163

Sources:

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface. - CVE: CVE-2026-39832 - Affected component: golang.org/x/crypto in nats runtime image - Severity: HIGH - In-repo version(s): golang.org/x/crypto v0.37.0 in nats-server (nats:2.10) - Project impact: The shipped NATS runtime binary embeds a vulnerable x/crypto release, so affected SSH authentication callback handling remains exposed until the runtime image is refreshed. - Remediation: Upgrade to a NATS image built with golang.org/x/crypto 0.52.0 or newer. Counters for this run: - unaddressed critical CVEs: 6 - unaddressed medium/low CVEs: 119 - unaddressed total CVEs: 163 Sources: - https://nvd.nist.gov/vuln/detail/CVE-2026-39832 - https://avd.aquasec.com/nvd/cve-2026-39832
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#147
No description provided.