Skip to content

Bump go-jose to 4.1.4 to fix CVE-2026-34986#8764

Open
jotamartos wants to merge 2 commits intothanos-io:mainfrom
jotamartos:bump-go-jose
Open

Bump go-jose to 4.1.4 to fix CVE-2026-34986#8764
jotamartos wants to merge 2 commits intothanos-io:mainfrom
jotamartos:bump-go-jose

Conversation

@jotamartos
Copy link
Copy Markdown

@jotamartos jotamartos commented Apr 10, 2026

  • I added CHANGELOG entry for this change.
  • Change is not relevant to the end user.

Changes

Versions lower than 4.1.4 are affected by CVE-2026-34986. Bumping package to the latest version to avoid security issues.

bin/thanos (gobinary)
=====================
Total: 13 (UNKNOWN: 3, LOW: 1, MEDIUM: 5, HIGH: 4, CRITICAL: 0)

┌──────────────────────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬────────────────┬─────────────────────────────────────────────────────────────┐
│                           Library                            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version  │                            Title                            │
├──────────────────────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼────────────────┼─────────────────────────────────────────────────────────────┤
│ github.com/go-jose/go-jose/v4                                │ CVE-2026-34986 │ HIGH     │ fixed  │ v4.1.3            │ 4.1.4          │ github.com/go-jose/go-jose/v3:                              │
│                                                              │                │          │        │                   │                │ github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service   │
│                                                              │                │          │        │                   │                │ via crafted JSON Web Encryption...                          │
│                                                              │                │          │        │                   │                │ https://avd.aquasec.com/nvd/cve-2026-34986                  │

Verification

@jotamartos jotamartos changed the title Bump go-jose to 4.1.4 Bump go-jose to 4.1.4 to fix CVE-2026-34986 Apr 10, 2026
Signed-off-by: Jota Martos <jotamartos@gmail.com>
Signed-off-by: Jota Martos <jotamartos@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant