fix: bump go-jose/go-jose/v4 to v4.1.4 (CVE-2026-34986) by Shelnutt2 · Pull Request #25263 · coder/coder
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Merged
Conversation
Shelnutt2
commented
May 13, 2026
Shelnutt2
commented
Contributor
Summary
Bumps github.com/go-jose/go-jose/v4 from v4.1.3 to v4.1.4 on the release/2.29 branch to fix a JWE decryption panic.
| CVE | Severity | Advisory |
|---|---|---|
| CVE-2026-34986 | High | NVD |
| GHSA-78h2-9frx-2jm8 | High | GitHub |
Changes
go.mod:go-jose/go-jose/v4v4.1.3 -> v4.1.4go.sum: updated checksums
No code changes; dependency-only bump.
Generated by Coder Agents (session)
Upgrade github.com/go-jose/go-jose/v4 from v4.1.3 to v4.1.4 to fix a JWE decryption panic vulnerability (CVE-2026-34986, GHSA-78h2-9frx-2jm8). Ref: ENT-55, ENT-65
github-actions
Bot
assigned
Shelnutt2
Shelnutt2
requested review from
f0ssel and
jdomeracki-coder
Shelnutt2
added
dependencies
labels
Shelnutt2
changed the title
fix(deps): bump go-jose/go-jose/v4 to v4.1.4 (CVE-2026-34986)
fix: bump go-jose/go-jose/v4 to v4.1.4 (CVE-2026-34986)
f0ssel
approved these changes
Shelnutt2
deleted the
fix/upgrade-go-jose-v2.29
branch
github-actions
Bot
locked and limited conversation to collaborators
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.