Skip to content

fix CVE-2026-34986 bump go-jose/v4 v4.1.4#4776

Open
anandrkskd wants to merge 1 commit into
dexidp:v2.43.xfrom
anandrkskd:CVE-2026-34986
Open

fix CVE-2026-34986 bump go-jose/v4 v4.1.4#4776
anandrkskd wants to merge 1 commit into
dexidp:v2.43.xfrom
anandrkskd:CVE-2026-34986

Conversation

@anandrkskd
Copy link
Copy Markdown

Overview

Current go-jose version v4.1.0 is effected by CVE-2026-34986. And is fixed in go-jose v4.1.4 and above version.

What this PR does / why we need it

Future code changes or dependency updates could introduce JWE parsing paths without anyone noticing the vulnerability. This is resolved by updating the dependency.

Special notes for your reviewer

Signed-off-by: Anand Kumar Singh <anandrkskd@gmail.com>
Copy link
Copy Markdown

@aali309 aali309 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@nabokihms nabokihms added the dependencies Pull requests that update a dependency file label May 6, 2026
@nabokihms
Copy link
Copy Markdown
Member

This is a PR to the outdated release. Is this for maintainers or opened by mistake?

@anandrkskd
Copy link
Copy Markdown
Author

This is a PR to the outdated release. Is this for maintainers or opened by mistake?

I will create PR to update it in master. Can you share what versions are supported?

@cardoe
Copy link
Copy Markdown
Contributor

cardoe commented May 11, 2026

This is a PR to the outdated release. Is this for maintainers or opened by mistake?

I will create PR to update it in master. Can you share what versions are supported?

The latest v2.x release is supported. You're targeting and old patch release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants