—
GO-2026-5932
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
Details
The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.
If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/golang.org/x/crypto
Introduced in:
0No fixed version published yet for golang.org/x/crypto (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://go.dev/issue/44226[REPORT]