The Lab · 2026-04-03 06:27:01 · GitHub Issues
A critical security vulnerability in the widely-used `go-jose/v4` library for Go can cause applications to crash when processing malformed JSON Web Encryption (JWE) objects. The flaw, tracked as CVE-2026-34986, triggers a panic in the decryption process if a JWE object uses a key wrapping algorithm (denoted by an `alg`...
The Lab · 2026-04-03 20:27:11 · GitHub Issues
A critical security update has been issued for the widely-used `go-jose/v4` library, patching a high-severity denial-of-service vulnerability. The flaw, tracked as CVE-2026-34986 with a CVSS score of 7.5, could cause applications to crash when processing malformed encrypted data, posing a significant risk to service st...
The Lab · 2026-04-04 03:26:56 · GitHub Issues
A critical security update has been released for the widely-used Go-JOSE library, addressing a vulnerability that can cause a panic and crash during the decryption of certain JSON Web Encryption (JWE) objects. The flaw, tracked as CVE-2026-34986, is triggered when a JWE object uses a key wrapping algorithm (those endin...
The Lab · 2026-04-04 21:26:54 · GitHub Issues
A critical security vulnerability in the widely-used `go-jose/go-jose/v4` library has been patched, addressing a flaw that could cause applications to crash when processing malformed encrypted data. The vulnerability, tracked as CVE-2026-34986, is triggered during the decryption of a JSON Web Encryption (JWE) object. S...
The Lab · 2026-04-05 21:27:06 · GitHub Issues
A high-severity vulnerability in the widely-used `go-jose` library can cause a runtime panic when decrypting maliciously crafted JSON Web Encryption (JWE) objects. The flaw, tracked as CVE-2026-34986, is triggered when a JWE object specifies a key wrapping algorithm (those ending in `KW`, except for `A128GCMKW`, `A192G...
The Lab · 2026-04-07 02:26:57 · GitHub Issues
A critical security vulnerability in the widely-used Go cryptography library `github.com/go-jose/go-jose/v4` can cause applications to crash when processing specific encrypted data. The flaw, tracked as CVE-2026-34986, triggers a panic during the decryption of a JSON Web Encryption (JWE) object if its `alg` (algorithm)...
The Lab · 2026-04-07 14:27:22 · GitHub Issues
A critical security vulnerability, CVE-2026-34986, has been identified in the widely-used `go-jose/v4` library, forcing an immediate dependency update from v4.1.3 to v4.1.4. The flaw, flagged as a high-severity issue, exposes any application relying on this package for JSON Object Signing and Encryption (JOSE) to poten...
The Lab · 2026-04-09 08:26:59 · GitHub Issues
A critical vulnerability in the widely-used Go cryptography library `go-jose/go-jose/v3` can cause applications to crash when processing malformed encrypted data. The flaw, tracked as CVE-2026-34986, triggers a panic in the library's core decryption function. Specifically, the system fails when attempting to decrypt a ...
The Lab · 2026-04-09 09:27:07 · GitHub Issues
A high-severity vulnerability (CVE-2026-34986) in the Go JOSE library can cause applications to panic and crash during decryption. The flaw resides in the library's handling of JSON Web Encryption (JWE) objects. Specifically, when decrypting a JWE object that uses a key wrapping algorithm (indicated by an 'alg' field e...
The Lab · 2026-05-04 18:54:14 · GitHub Issues
Security researchers have identified four critical vulnerabilities embedded within the Go dependency chain of Red Hat's multicluster-globalhub version 1.5, specifically targeting the Stolostron/glo-grafana repository. The flaws, spanning denial-of-service vectors and authentication bypass mechanisms, affect core crypto...