Improper input validation in go-jose - CVE-2026-34986
Published: April 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in JWE decryption in key_wrap.go when processing a JWE object with a key wrapping algorithm and an empty encrypted_key field. A remote attacker can send a specially crafted JWE object to cause a denial of service.
The issue is reachable through ParseEncrypted(), ParseEncryptedJSON(), or ParseEncryptedCompact() followed by Decrypt(), and applications are affected only if accepted key algorithms include key wrapping algorithms.
Affected software
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
openEuler
Anolis OS
Container Projects skopeo
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
opkssh
opentelemetry-collector (Red Hat package)
skopeo-debugsource
skopeo-debuginfo
containers-common
skopeo
apptainer
skopeo (Red Hat package)
skopeo-tests
skopeo-doc
buildah
buildah-debuginfo
buildah-debugsource
buildah (Red Hat package)
buildah-tests
cri-o1.34
containerd
openbao
docker-distribution
google-cloud-sap-agent
release-notes-susemanager-proxy
release-notes-susemanager
podman (Red Hat package)
podman
moby-engine
image-builder (Red Hat package)
osbuild-composer (Red Hat package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2026-34986
Container Projects skopeo - update to 1.22.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
opkssh - addressed in versions 0.13.0-8.el10_1, 0.13.0-8.el10_3, 0.13.0-8.fc42, 0.13.0-8.fc43, 0.13.0-8.fc44
opentelemetry-collector (Red Hat package) - addressed in versions 0.144.0-2.el9_4, 0.144.0-2.el9_6, 0.144.0-2.el10_0
skopeo-debugsource - addressed in versions 1.1.0-16, 1.8.0-10, 1.14.2-9
skopeo-debuginfo - addressed in versions 1.1.0-16, 1.8.0-10, 1.14.2-9
containers-common - update to 1.1.0-16
skopeo - addressed in versions 1.1.0-16, 1.8.0-10, 1.14.2-9
apptainer - addressed in versions 1.5.0-1.el8, 1.5.0-1.el9, 1.5.0-1.el10_1, 1.5.0-1.el10_2, 1.5.0-1.el10_3
skopeo (Red Hat package) - addressed in versions 1.11.4-0.1.el9_2.6, 1.14.6-1.el9_4, 1.18.1-3.el10_0.1
skopeo-tests - update to 1.14.2-9
skopeo-doc - update to 1.18.2-1
skopeo-tests - update to 1.18.2-1
skopeo - update to 1.18.2-1
skopeo - addressed in versions 1.22.1-2.fc42, 1.22.1-2.fc43, 1.22.1-2.fc44, 1.22.2-1.fc42, 1.22.2-1.fc44
buildah - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debuginfo - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debugsource - addressed in versions 1.26.1-13, 1.34.1-15
buildah (Red Hat package) - addressed in versions 1.29.7-1.el9_2.5, 1.33.15-1.el9_4.1
buildah-tests - update to 1.34.1-15
cri-o1.34 - addressed in versions 1.34.11-1.fc43, 1.34.11-1.fc44, 1.34.11-1.fc45
buildah - addressed in versions 1.43.1-1.fc42, 1.43.1-1.fc44
containerd - update to 2.3.2-1.fc45
openbao - addressed in versions 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44
Multicluster Engine for Kubernetes - update to 2.6.12
docker-distribution - update to 3.1.1-1.fc45
google-cloud-sap-agent - addressed in versions 3.12-6.63.1, 3.12-150100.3.66.1
release-notes-susemanager-proxy - update to 4.3.18-150400.3.110.2
release-notes-susemanager - update to 4.3.18-150400.3.154.2
podman (Red Hat package) - addressed in versions 4.4.1-22.el9_2.11, 4.9.4-20.el9_4.3, 5.4.0-15.el10_0.1, 5.4.0-20.el9_6.3
Red Hat OpenShift Container Platform - addressed in versions 4.17.55, 4.18.45, 4.19.35, 4.21.20, 4.21.26, 4.22.1, 4.22.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
podman - addressed in versions 5.8.2-1.fc42, 5.8.2-1.fc44
OpenShift Logging - update to 6.0.15
moby-engine - addressed in versions 29.4.0-1.fc42, 29.4.0-1.fc43, 29.4.0-1.fc44, 29.4.0-1.fc45
image-builder (Red Hat package) - update to 52.1-1.el10_2
osbuild-composer (Red Hat package) - addressed in versions 101.3-4.el9_4.2, 101.5-1.el8_10, 132.2-8.el9_6, 134.1-9.el10_0
External References
Related Security Bulletins
- Improper input validation in go-jose
- skopeo update for go-jose
- Fedora 45 update for moby-engine
- Fedora 44 update for moby-engine
- Fedora 43 update for moby-engine
- Fedora 42 update for moby-engine
- Fedora EPEL 10.1 update for opkssh
- Fedora 44 update for opkssh
- Fedora EPEL 10.3 update for opkssh
- Fedora 43 update for opkssh
- Fedora 42 update for opkssh
- Fedora 44 update for skopeo
- Fedora 43 update for skopeo
- Fedora 42 update for skopeo
- Fedora 44 update for buildah, podman, skopeo
- Fedora 42 update for buildah, podman, skopeo
- Fedora EPEL 8 update for openbao
- Fedora EPEL 10.3 update for openbao
- Fedora 43 update for openbao
- Fedora EPEL 10.1 update for openbao
- Fedora 44 update for openbao
- Fedora 42 update for openbao
- Fedora EPEL 10.2 update for openbao
- Fedora EPEL 9 update for openbao
- Fedora 45 update for docker-distribution
- Fedora EPEL 8 update for apptainer
- Fedora EPEL 10.2 update for apptainer
- Fedora EPEL 10.1 update for apptainer
- Fedora EPEL 10.3 update for apptainer
- Fedora EPEL 9 update for apptainer
- Red Hat Enterprise Linux 10 update for skopeo
- Red Hat Enterprise Linux 10 update for podman
- SUSE update for google-cloud-sap-agent
- SUSE update for google-cloud-sap-agent
- IBM Watson Speech Services Cartridge update for Go JOSE
- SUSE update for Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 9 update for buildah
- Improper input validation in Red Hat OpenShift Container Platform 4.22
- Red Hat Enterprise Linux 10 update for osbuild-composer
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.19
- Fedora 45 update for containerd
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- openEuler 24.03 LTS SP1 update for buildah
- openEuler 22.03 LTS SP4 update for buildah
- openEuler 24.03 LTS SP4 update for buildah
- openEuler 24.03 LTS SP3 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 10 update for opentelemetry-collector
- Red Hat Enterprise Linux 9 update for opentelemetry-collector
- Red Hat Enterprise Linux 9 update for opentelemetry-collector
- Red Hat Enterprise Linux 10 update for image-builder
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Multiple vulnerabilities in OpenShift Logging 6.0
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for skopeo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Red Hat Enterprise Linux 8 update for osbuild-composer
- Anolis OS update for skopeo
- Fedora 45 update for cri-o1.34
- Fedora 44 update for cri-o1.34
- Fedora 43 update for cri-o1.34
- openEuler 24.03 LTS SP1 update for skopeo
- openEuler 22.03 LTS SP4 update for skopeo
- openEuler 20.03 LTS SP4 update for skopeo
- openEuler 24.03 LTS SP4 update for skopeo
- openEuler 24.03 LTS SP3 update for skopeo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21