Skip to content

fix(cve): cve-2026-34986 - go-jose dos#382

Open
vmrh21 wants to merge 1 commit into
red-hat-data-services:rhoai-3.4-ea.2from
vmrh21:fix/cve-2026-34986-go-jose-rhoai-3.4-ea.2-attempt-1
Open

fix(cve): cve-2026-34986 - go-jose dos#382
vmrh21 wants to merge 1 commit into
red-hat-data-services:rhoai-3.4-ea.2from
vmrh21:fix/cve-2026-34986-go-jose-rhoai-3.4-ea.2-attempt-1

Conversation

@vmrh21

@vmrh21 vmrh21 commented Apr 21, 2026

Copy link
Copy Markdown

summary

update github.com/go-jose/go-jose/v4 from v4.1.1 to v4.1.4 to resolve denial of service vulnerability via crafted jwe object (cve-2026-34986).

cve details

  • cve id: cve-2026-34986
  • package: github.com/go-jose/go-jose/v4
  • severity: high (cvss 7.5)
  • vulnerable versions: < v4.1.4
  • fixed version: v4.1.4
  • jira: rhoaieng-56853

changes

  • update github.com/go-jose/go-jose/v4 from v4.1.1 to v4.1.4 in maas-api/go.mod
  • run go mod tidy to update maas-api/go.sum

test plan

  • dependency version verified at v4.1.4
  • ci/cd pipeline passes

🤖 generated with claude code

update github.com/go-jose/go-jose/v4 from v4.1.1 to v4.1.4 to resolve
denial of service via crafted jwe object.

resolves: rhoaieng-56853

co-authored-by: claude opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant