Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 171

Количество 171

rocky логотип

RLSA-2026:19017

4 месяца назад

Important: podman security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19017

2 месяца назад

ELSA-2026-19017: podman security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:33722

3 месяца назад

Important: container-tools:rhel8 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-33722

3 месяца назад

ELSA-2026-33722: container-tools:ol8 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:23228

3 месяца назад

Important: image-builder security update

EPSS: Низкий
rocky логотип

RLSA-2026:22937

3 месяца назад

Important: image-builder security update

EPSS: Низкий
rocky логотип

RLSA-2026:19353

4 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:19135

4 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-23228

12 дней назад

ELSA-2026-23228: image-builder security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22937

2 месяца назад

ELSA-2026-22937: image-builder security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:22714

3 месяца назад

Important: osbuild-composer security update

EPSS: Низкий
rocky логотип

RLSA-2026:22450

3 месяца назад

Important: osbuild-composer security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22714

около 1 месяца назад

ELSA-2026-22714: osbuild-composer security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22450

около 1 месяца назад

ELSA-2026-22450: osbuild-composer security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-34986

5 месяцев назад

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-34986

5 месяцев назад

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-34986

5 месяцев назад

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reac

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-34986

5 месяцев назад

Go JOSE provides an implementation of the Javascript Object Signing an ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-25679

6 месяцев назад

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-25679

6 месяцев назад

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:19017

Important: podman security update

4 месяца назад
oracle-oval логотип
ELSA-2026-19017

ELSA-2026-19017: podman security update (IMPORTANT)

2 месяца назад
rocky логотип
RLSA-2026:33722

Important: container-tools:rhel8 security, bug fix, and enhancement update

3 месяца назад
oracle-oval логотип
ELSA-2026-33722

ELSA-2026-33722: container-tools:ol8 security, bug fix, and enhancement update (IMPORTANT)

3 месяца назад
rocky логотип
RLSA-2026:23228

Important: image-builder security update

3 месяца назад
rocky логотип
RLSA-2026:22937

Important: image-builder security update

3 месяца назад
rocky логотип
RLSA-2026:19353

Important: opentelemetry-collector security update

4 месяца назад
rocky логотип
RLSA-2026:19135

Important: opentelemetry-collector security update

4 месяца назад
oracle-oval логотип
ELSA-2026-23228

ELSA-2026-23228: image-builder security update (IMPORTANT)

12 дней назад
oracle-oval логотип
ELSA-2026-22937

ELSA-2026-22937: image-builder security update (IMPORTANT)

2 месяца назад
rocky логотип
RLSA-2026:22714

Important: osbuild-composer security update

3 месяца назад
rocky логотип
RLSA-2026:22450

Important: osbuild-composer security update

3 месяца назад
oracle-oval логотип
ELSA-2026-22714

ELSA-2026-22714: osbuild-composer security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-22450

ELSA-2026-22450: osbuild-composer security update (IMPORTANT)

около 1 месяца назад
ubuntu логотип
CVE-2026-34986

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-34986

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also r...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-34986

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reac

CVSS3: 7.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-34986

Go JOSE provides an implementation of the Javascript Object Signing an ...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-25679

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-25679

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVSS3: 7.5
1%
Низкий
6 месяцев назад

Уязвимостей на страницу