Количество 40
Количество 40
GHSA-78h2-9frx-2jm8
Go JOSE Panics in JWE decryption
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reac
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing an ...
openSUSE-SU-2026:20669-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:1938-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:1935-1
Security update for google-cloud-sap-agent
ROS-20260506-73-0003
Уязвимость golang-github-jose
RLSA-2026:19186
Important: buildah security update
RLSA-2026:19173
Important: podman security update
RLSA-2026:10135
Important: buildah security update
ELSA-2026-19186
ELSA-2026-19186: buildah security update (IMPORTANT)
ELSA-2026-19173
ELSA-2026-19173: podman security update (IMPORTANT)
ELSA-2026-10135
ELSA-2026-10135: buildah security update (IMPORTANT)
openSUSE-SU-2026:20816-1
Security update for alloy
openSUSE-SU-2026:20711-1
Security update for hauler
RLSA-2026:19017
Important: podman security update
openSUSE-SU-2026:20686-1
Security update for distribution
SUSE-SU-2026:2640-1
Security update for containerd
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-78h2-9frx-2jm8 Go JOSE Panics in JWE decryption | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reac | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing an ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20669-1 Security update for google-cloud-sap-agent | 0% Низкий | около 2 месяцев назад | ||
SUSE-SU-2026:1938-1 Security update for google-cloud-sap-agent | 0% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:1935-1 Security update for google-cloud-sap-agent | 0% Низкий | около 1 месяца назад | ||
ROS-20260506-73-0003 Уязвимость golang-github-jose | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
RLSA-2026:19186 Important: buildah security update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:19173 Important: podman security update | 0% Низкий | 26 дней назад | ||
RLSA-2026:10135 Important: buildah security update | 0% Низкий | 2 месяца назад | ||
ELSA-2026-19186 ELSA-2026-19186: buildah security update (IMPORTANT) | 17 дней назад | |||
ELSA-2026-19173 ELSA-2026-19173: podman security update (IMPORTANT) | 17 дней назад | |||
ELSA-2026-10135 ELSA-2026-10135: buildah security update (IMPORTANT) | 2 месяца назад | |||
openSUSE-SU-2026:20816-1 Security update for alloy | около 1 месяца назад | |||
openSUSE-SU-2026:20711-1 Security update for hauler | около 2 месяцев назад | |||
RLSA-2026:19017 Important: podman security update | 30 дней назад | |||
openSUSE-SU-2026:20686-1 Security update for distribution | около 2 месяцев назад | |||
SUSE-SU-2026:2640-1 Security update for containerd | 2 дня назад |
Уязвимостей на страницу