← العودة للجدول
CVE-2026-34986
CVE-2026-34986 — A flaw was found in Go JOSE, a library for handling JSON Web Encryption (JWE) ob
📅 2026-06-08
🟠 High 🔥 No CIRCL CVE DDoS DDoS CVSS 7.5

📋 الوصف الكامل

A flaw was found in Go JOSE, a library for handling JSON Web Encryption (JWE) objects. A remote attacker could exploit this vulnerability by providing a specially crafted JWE object. When decrypting such an object, if a key wrapping algorithm is specified but the encrypted key field is empty, the application can crash. This leads to a denial of service (DoS), making the affected service unavailabl

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

DDoS

🔗 CVE ID

CVE-2026-34986

📡 المصدر

CIRCL CVE

✅ الحلول والتخفيف

Refer to CVE-2026-34986 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←