Skip to content

Fix/CVE 2026 34986 go jose go OIDC#581

Merged
lakhansamani merged 3 commits intomainfrom
fix/cve-2026-34986-go-jose-go-oidc
Apr 6, 2026
Merged

Fix/CVE 2026 34986 go jose go OIDC#581
lakhansamani merged 3 commits intomainfrom
fix/cve-2026-34986-go-jose-go-oidc

Conversation

@lakhansamani
Copy link
Copy Markdown
Contributor

What does this PR do?

Fix CV issues with aws + docker image

Which issue(s) does this PR fix?

If this PR affects any API reference documentation, please share the updated endpoint references

- Bump github.com/go-jose/go-jose/v4 to v4.1.4 (patched for CVE-2026-34986).
- Upgrade github.com/coreos/go-oidc/v3 to v3.17.0 so the OIDC stack uses
  go-jose/v4 only; removes the indirect go-jose/v3 dependency.

Made-with: Cursor
@lakhansamani lakhansamani merged commit 9fd200c into main Apr 6, 2026
@lakhansamani lakhansamani deleted the fix/cve-2026-34986-go-jose-go-oidc branch April 6, 2026 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant