Improper input validation in go-jose - CVE-2026-34986

 

Improper input validation in go-jose - CVE-2026-34986

Published: April 14, 2026


Vulnerability identifier: #VU125945
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34986
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in JWE decryption in key_wrap.go when processing a JWE object with a key wrapping algorithm and an empty encrypted_key field. A remote attacker can send a specially crafted JWE object to cause a denial of service.

The issue is reachable through ParseEncrypted(), ParseEncryptedJSON(), or ParseEncryptedCompact() followed by Decrypt(), and applications are affected only if accepted key algorithms include key wrapping algorithms.


Affected software

go-jose
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
openEuler
Anolis OS
Container Projects skopeo
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
opkssh
opentelemetry-collector (Red Hat package)
skopeo-debugsource
skopeo-debuginfo
containers-common
skopeo
apptainer
skopeo (Red Hat package)
skopeo-tests
skopeo-doc
buildah
buildah-debuginfo
buildah-debugsource
buildah (Red Hat package)
buildah-tests
cri-o1.34
containerd
openbao
docker-distribution
google-cloud-sap-agent
release-notes-susemanager-proxy
release-notes-susemanager
podman (Red Hat package)
podman
moby-engine
image-builder (Red Hat package)
osbuild-composer (Red Hat package)
Red Hat OpenShift Container Platform

How to mitigate CVE-2026-34986

Install security update from vendor's website.

go-jose - addressed in versions 3.0.5, 4.1.4
Container Projects skopeo - update to 1.22.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
opkssh - addressed in versions 0.13.0-8.el10_1, 0.13.0-8.el10_3, 0.13.0-8.fc42, 0.13.0-8.fc43, 0.13.0-8.fc44
opentelemetry-collector (Red Hat package) - addressed in versions 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0
skopeo-debugsource - addressed in versions 1.1.0-16, 1.8.0-10, 1.14.2-9
skopeo-debuginfo - addressed in versions 1.1.0-16, 1.8.0-10, 1.14.2-9
containers-common - update to 1.1.0-16
skopeo - addressed in versions 1.1.0-16, 1.8.0-10, 1.14.2-9
apptainer - addressed in versions 1.5.0-1.el8, 1.5.0-1.el9, 1.5.0-1.el10_1, 1.5.0-1.el10_2, 1.5.0-1.el10_3
skopeo (Red Hat package) - addressed in versions 1.11.4-0.1.el9_2.6, 1.14.6-1.el9_4, 1.18.1-3.el10_0.1
skopeo-tests - update to 1.14.2-9
skopeo-doc - update to 1.18.2-1
skopeo-tests - update to 1.18.2-1
skopeo - update to 1.18.2-1
skopeo - addressed in versions 1.22.1-2.fc42, 1.22.1-2.fc43, 1.22.1-2.fc44, 1.22.2-1.fc42, 1.22.2-1.fc44
buildah - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debuginfo - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debugsource - addressed in versions 1.26.1-13, 1.34.1-15
buildah (Red Hat package) - addressed in versions 1.29.7-1.el9_2.5, 1.33.15-1.el9_4.1
buildah-tests - update to 1.34.1-15
cri-o1.34 - addressed in versions 1.34.11-1.fc43, 1.34.11-1.fc44, 1.34.11-1.fc45
buildah - addressed in versions 1.43.1-1.fc42, 1.43.1-1.fc44
containerd - update to 2.3.2-1.fc45
openbao - addressed in versions 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44
Multicluster Engine for Kubernetes - update to 2.6.12
docker-distribution - update to 3.1.1-1.fc45
google-cloud-sap-agent - addressed in versions 3.12-6.63.1, 3.12-150100.3.66.1
release-notes-susemanager-proxy - update to 4.3.18-150400.3.110.2
release-notes-susemanager - update to 4.3.18-150400.3.154.2
podman (Red Hat package) - addressed in versions 4.4.1-22.el9_2.11, 4.9.4-20.el9_4.3, 5.4.0-15.el10_0.1, 5.4.0-20.el9_6.3
Red Hat OpenShift Container Platform - addressed in versions 4.17.55, 4.18.45, 4.19.35, 4.21.20, 4.21.26, 4.22.1, 4.22.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
podman - addressed in versions 5.8.2-1.fc42, 5.8.2-1.fc44
OpenShift Logging - update to 6.0.15
moby-engine - addressed in versions 29.4.0-1.fc42, 29.4.0-1.fc43, 29.4.0-1.fc44, 29.4.0-1.fc45
image-builder (Red Hat package) - update to 52.1-1.el10_2
osbuild-composer (Red Hat package) - addressed in versions 101.3-4.el9_4.2, 101.5-1.el8_10, 132.2-8.el9_6, 134.1-9.el10_0

External References

Related Security Bulletins