CVE-2026-34986General(go-jose_project / go-jose)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch go-jose_project go-jose systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248CWE-131

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go-jose

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
go-jose

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-17: 104-0604-17
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-061
General1
2026-04-171
Patch1
Full discourse2 posts
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical DoS bug CVE-2026-34986 hits Fedora 43 Podman, Buildah, Skopeo via crafted JWE objects, fixes shipped in skopeo 1.22.2, podman 5.8.2, buildah 1.43.1 on April 14. https://threatcluster.io/cluster/critical-dos-vulnerabilities-in-fedora-43-podman-buildah-and-bd48a0eb

    Post summary

    A critical DoS vulnerability (CVE-2026-34986) affecting Fedora 43's Podman, Buildah, and Skopeo was disclosed, and it has been patched with new releases released on April 14.

    0000062
    155 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34986 Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web S… https://www.cve.org/CVERecord?id=CVE-2026-34986

    Post summary

    The tweet merely references CVE-2026-34986 in relation to Go JOSE, offering no further details on the vulnerability or its exploitation.

    00000129
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgo-jose_projectgo-jose---

Explore more