The Lab · 2026-03-27 13:27:20 · GitHub Issues
A critical path traversal vulnerability in the widely used `basic-ftp` Node.js library has been disclosed, allowing a malicious FTP server to write files anywhere on a victim's system. The flaw, tracked as CVE-2026-27699, resides in the library's `downloadToDir()` method. By exploiting this, an attacker could achieve a...
The Lab · 2026-04-03 06:27:05 · GitHub Issues
A critical security vulnerability in the widely-used Go-JOSE library triggers a panic during JWE decryption, forcing a mandatory patch to version 4.1.4. The flaw, tracked as CVE-2026-34986 and GHSA-78h2-9frx-2jm8, is a denial-of-service risk that can crash applications when processing malformed encrypted data. This is ...
The Lab · 2026-04-03 10:27:06 · GitHub Issues
A critical vulnerability in the widely-used Go-JOSE library triggers a runtime panic when processing malformed JSON Web Encryption (JWE) objects. The flaw, tracked as CVE-2026-34986, resides in the key unwrapping logic and can crash any service that attempts to decrypt a JWE with a specific, anomalous structure. This c...
The Lab · 2026-04-03 19:27:01 · GitHub Issues
A critical security vulnerability in the widely-used `go-jose/go-jose/v4` library has been patched, addressing a flaw that could cause applications to crash when processing malformed encrypted data. The vulnerability, tracked as CVE-2026-34986, resides in the library's handling of JSON Web Encryption (JWE) objects. Spe...
The Lab · 2026-04-04 03:26:53 · GitHub Issues
A critical security update for the widely-used Go-JOSE library patches a vulnerability that can cause a denial-of-service panic during JWE decryption. The flaw, tracked as CVE-2026-34986, is triggered when decrypting a JSON Web Encryption (JWE) object that uses a key wrapping algorithm (ending in `KW`) but contains an ...
The Lab · 2026-04-04 03:26:54 · GitHub Issues
A critical security vulnerability in the widely-used Go cryptography library `github.com/go-jose/go-jose/v4` has been patched. The flaw, tracked as CVE-2026-34986, can cause a runtime panic when decrypting certain malformed JSON Web Encryption (JWE) objects. This vulnerability is triggered in a specific but reachable c...
The Lab · 2026-04-04 15:27:01 · GitHub Issues
A critical security vulnerability in the widely-used Go-JOSE library forces an immediate patch to version 4.1.4. The flaw, tracked as CVE-2026-34986, causes a runtime panic when the library attempts to decrypt a JSON Web Encryption (JWE) object that uses a key wrapping algorithm (identified by an `alg` field ending in ...
The Lab · 2026-04-04 21:26:54 · GitHub Issues
A critical security vulnerability in the widely-used `go-jose/go-jose/v4` library has been patched, addressing a flaw that could cause applications to crash when processing malformed encrypted data. The vulnerability, tracked as CVE-2026-34986, is triggered during the decryption of a JSON Web Encryption (JWE) object. S...
The Lab · 2026-04-04 21:26:56 · GitHub Issues
A critical security vulnerability in the widely-used Go cryptography library `go-jose/go-jose/v3` has been patched, addressing a flaw that could cause applications to crash when processing malformed encrypted data. The vulnerability, tracked as CVE-2026-34986, is triggered during the decryption of a JSON Web Encryption...
The Lab · 2026-04-05 03:27:03 · GitHub Issues
A critical security flaw in the widely-used `github.com/go-jose/go-jose/v4` library has been patched, addressing a vulnerability that could cause applications to crash when processing malformed encrypted data. The issue, tracked as CVE-2026-34986, triggers a panic during the decryption of specific JSON Web Encryption (...
The Lab · 2026-04-05 03:27:05 · GitHub Issues
A critical security vulnerability in the widely-used `github.com/go-jose/go-jose/v4` library can cause a panic and crash in applications processing certain encrypted data. The flaw, tracked as CVE-2026-34986, is triggered when decrypting a JSON Web Encryption (JWE) object that uses a specific type of key wrapping algor...
The Lab · 2026-04-06 07:27:00 · GitHub Issues
A critical security vulnerability in the widely-used `go-jose/go-jose/v4` library could cause applications to crash when processing malformed encrypted data. The flaw, tracked as CVE-2026-34986, triggers a panic during the decryption of a JSON Web Encryption (JWE) object under specific, exploitable conditions. This is ...
The Lab · 2026-04-10 23:22:33 · GitHub Issues
A critical security flaw in the widely-used Go-JOSE library forces a mandatory patch to version 4.1.4. The vulnerability, tracked as CVE-2026-34986, causes the library to panic and crash when attempting to decrypt a specially crafted JSON Web Encryption (JWE) object. This is not a theoretical weakness; it is a denial-o...
The Lab · 2026-04-18 03:22:36 · GitHub Issues
A critical vulnerability in the widely-used MailKit library allows attackers to inject malicious commands and force weaker authentication, compromising the security of countless email clients and applications. The flaw, tracked as GHSA-9j88-vvj5-vhgr, is a STARTTLS Response Injection vulnerability that enables a Man-in...