Количество 55
Количество 55
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reac
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing an ...
openSUSE-SU-2026:20669-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:1938-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:1935-1
Security update for google-cloud-sap-agent
ROS-20260506-73-0003
Уязвимость golang-github-jose
RLSA-2026:19186
Important: buildah security update
RLSA-2026:19173
Important: podman security update
RLSA-2026:10135
Important: buildah security update
GHSA-78h2-9frx-2jm8
Go JOSE Panics in JWE decryption
ELSA-2026-19186
ELSA-2026-19186: buildah security update (IMPORTANT)
ELSA-2026-19173
ELSA-2026-19173: podman security update (IMPORTANT)
ELSA-2026-10135
ELSA-2026-10135: buildah security update (IMPORTANT)
openSUSE-SU-2026:20816-1
Security update for alloy
openSUSE-SU-2026:20711-1
Security update for hauler
RLSA-2026:19017
Important: podman security update
ELSA-2026-19017
ELSA-2026-19017: podman security update (IMPORTANT)
openSUSE-SU-2026:21010-1
Security update for google-cloud-sap-agent
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reac | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing an ... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20669-1 Security update for google-cloud-sap-agent | 1% Низкий | 3 месяца назад | ||
SUSE-SU-2026:1938-1 Security update for google-cloud-sap-agent | 1% Низкий | 3 месяца назад | ||
SUSE-SU-2026:1935-1 Security update for google-cloud-sap-agent | 1% Низкий | 3 месяца назад | ||
ROS-20260506-73-0003 Уязвимость golang-github-jose | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
RLSA-2026:19186 Important: buildah security update | 1% Низкий | 3 месяца назад | ||
RLSA-2026:19173 Important: podman security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:10135 Important: buildah security update | 1% Низкий | 4 месяца назад | ||
GHSA-78h2-9frx-2jm8 Go JOSE Panics in JWE decryption | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ELSA-2026-19186 ELSA-2026-19186: buildah security update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-19173 ELSA-2026-19173: podman security update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-10135 ELSA-2026-10135: buildah security update (IMPORTANT) | 4 месяца назад | |||
openSUSE-SU-2026:20816-1 Security update for alloy | 3 месяца назад | |||
openSUSE-SU-2026:20711-1 Security update for hauler | 3 месяца назад | |||
RLSA-2026:19017 Important: podman security update | 2 месяца назад | |||
ELSA-2026-19017 ELSA-2026-19017: podman security update (IMPORTANT) | около 1 месяца назад | |||
openSUSE-SU-2026:21010-1 Security update for google-cloud-sap-agent | около 2 месяцев назад |
Уязвимостей на страницу