| Name | CVE-2026-34986 |
| Description | Go JOSE provides an implementation of the Javascript Object Signing an ... |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
The information below is based on the following data on fixed versions.
Notes
[trixie] - golang-github-go-jose-go-jose <no-dsa> (Minor issue)
[trixie] - golang-github-go-jose-go-jose.v3 <no-dsa> (Minor issue)
[trixie] - golang-gopkg-square-go-jose.v2 <no-dsa> (Minor issue)
[bookworm] - golang-gopkg-square-go-jose.v2 <no-dsa> (Minor issue)
[bullseye] - golang-gopkg-square-go-jose.v2 <postponed> (Minor issue)
[trixie] - golang-gopkg-square-go-jose.v1 <no-dsa> (Minor issue)
[bookworm] - golang-gopkg-square-go-jose.v1 <no-dsa> (Minor issue)
[bullseye] - golang-gopkg-square-go-jose.v1 <postponed> (Minor issue)
https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8
https://github.com/go-jose/go-jose/commit/0e59876635f3dbf46d7b5e97b52bb75a3f96e7d9 (v4.1.4)
https://github.com/go-jose/go-jose/commit/02464163e1e891db85257cb8860978a1c0226016 (v3.0.5)