| Release | Version |
|---|---|
| bullseye | 1.1.2-2 |
| bookworm | 1.1.2-4 |
| trixie | 1.1.2-4 |
| forky | 1.1.2-4 |
| sid | 1.1.2-4 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-34986 | vulnerable | vulnerable (no DSA) | vulnerable (no DSA) | vulnerable | vulnerable | Go JOSE provides an implementation of the Javascript Object Signing an ... |
| Bug | Description |
|---|---|
| CVE-2016-9123 | go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bi ... |
| CVE-2016-9122 | go-jose before 1.0.4 suffers from multiple signatures exploitation. Th ... |
| CVE-2016-9121 | go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH ... |