StackRadar

CVE-2026-34986

High

Advisory

Published 3 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
410
of 17,787 indexed, latest versions
Container images
405
deployed by those charts
Fix available
2 of 3
affected packages

Go JOSE Panics in JWE decryption

Carried by container images the latest versions of 410 of 17,787 indexed charts deploy, on 405 images.

Affected packageAffected versionsFixed inImages
github.com/go-jose/go-jose/v4golangv4.0.1, v4.0.2, v4.0.4, v4.0.5+4 more4.1.4282
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.2+2 more3.0.5170
github.com/go-jose/go-josegolangv2.6.3+incompatibleno fix listed4
OSV records
GHSA-78h2-9frx-2jm8
Also known as
GO-2026-4945

Charts affected

410 by stars
ChartLatestAffected imagesRadar Score
typhoontyphoonVerified publisher0.2.31 of 2See more

typhoon typhoon 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5

Open the chart page →

1,672
opencloudunxwaresVerified publisher0.2.32 of 13See more

opencloud unxwares 0.2.3

2 of the 13 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
github.com/go-jose/go-jose/v4@v4.1.0
4.1.4
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.0.5
3.0.5
4.1.4

Open the chart page →

45,392
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
github.com/go-jose/go-jose/v4@v4.1.3
4.1.4

Open the chart page →

696
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

1,114
ciliumvks-helm-chartsVerified publisher1.17.141 of 3See more

cilium vks-helm-charts 1.17.14

1 of the 3 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
quay.io/cilium/operator-generic:v1.17.14773886ec9337
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

4,124
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5

Open the chart page →

6,272
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.0
3.0.5
4.1.4

Open the chart page →

969
wexa-studiowexa-studio1.2.04 of 15See more

wexa-studio wexa-studio 1.2.0

4 of the 15 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
3.0.5
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
temporalio/server:1.29.1c1e3326b2ce1
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
temporalio/ui:2.44.00b36e00aad30
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

14,618
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

1,187
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5

Open the chart page →

9,381

Container images carrying it

405 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5
1
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
github.com/go-jose/go-jose/v4@v4.0.4
4.1.4
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
github.com/go-jose/go-jose/v4@v4.0.4
4.1.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
github.com/go-jose/go-jose/v4@v4.0.4
4.1.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
github.com/go-jose/go-jose/v4@v4.0.4
4.1.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
github.com/go-jose/go-jose/v4@v4.0.4
4.1.4
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
github.com/go-jose/go-jose/v4@v4.0.4
4.1.4
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.0.5
3.0.5
4.1.4
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5
1
ghcr.io/voyagermesh/gateway:v1.6.223f4da194134
github.com/go-jose/go-jose/v4@v4.1.2
4.1.4
1
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5
1
public.ecr.aws/cloudnatix/llmariner/session-manager-server:0.1.0-gfu-devb9537499ff9e
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
github.com/go-jose/go-jose/v4@v4.1.2
4.1.4
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.0.5
3.0.5
4.1.4
1
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
github.com/go-jose/go-jose/v4@v4.0.4
4.1.4
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
github.com/go-jose/go-jose/v4@v4.1.0
4.1.4
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5
1
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.0
3.0.5
4.1.4
1
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.0
3.0.5
4.1.4
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/go-jose/go-jose/v3@v3.0.1
3.0.5
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.0
3.0.5
4.1.4
1
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.0
3.0.5
4.1.4
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/go-jose/go-jose/v3@v3.0.1
3.0.5
1
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.0
3.0.5
4.1.4
1
quay.io/cilium/operator-generic:v1.17.14773886ec9337
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
quay.io/cilium/operator-generic:v1.15.1819c7281f5a4
github.com/go-jose/go-jose/v3@v3.0.1
3.0.5
1
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.3
3.0.5
4.1.4
1
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5
1
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
github.com/go-jose/go-jose/v4@v4.0.2
4.1.4
1
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
github.com/go-jose/go-jose@v2.6.3+incompatible
no fix listed
1
quay.io/kiali/kiali:v2.23.07652b1285f50
github.com/go-jose/go-jose/v4@v4.1.3
4.1.4
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
github.com/go-jose/go-jose/v4@v4.1.1
4.1.4
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.1
3.0.5
4.1.4
1
quay.io/oauth2-proxy/oauth2-proxy:v7.14.368336da945bd
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.3
3.0.5
4.1.4
1
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
github.com/go-jose/go-jose/v3@v3.0.3
github.com/go-jose/go-jose/v4@v4.0.4
3.0.5
4.1.4
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-jose/go-jose/v3@v3.0.1
3.0.5
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
github.com/go-jose/go-jose/v4@v4.1.3
4.1.4
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
github.com/go-jose/go-jose/v4@v4.1.3
4.1.4
1
quay.io/projectquay/clair:4.9.023329c3368e4
github.com/go-jose/go-jose/v3@v3.0.4
3.0.5
1
quay.io/rabbitmqoperator/messaging-topology-operator:1.18.1f97c36882244
github.com/go-jose/go-jose/v4@v4.1.1
4.1.4
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.