StackRadar

CVE-2026-34986

High

Advisory

Published 3 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
410
of 17,787 indexed, latest versions
Container images
405
deployed by those charts
Fix available
2 of 3
affected packages

Go JOSE Panics in JWE decryption

Carried by container images the latest versions of 410 of 17,787 indexed charts deploy, on 405 images.

Affected packageAffected versionsFixed inImages
github.com/go-jose/go-jose/v4golangv4.0.1, v4.0.2, v4.0.4, v4.0.5+4 more4.1.4282
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.2+2 more3.0.5170
github.com/go-jose/go-josegolangv2.6.3+incompatibleno fix listed4
OSV records
GHSA-78h2-9frx-2jm8
Also known as
GO-2026-4945

Charts affected

410 by stars
ChartLatestAffected imagesRadar Score
typhoontyphoonVerified publisher0.2.31 of 2See more

typhoon typhoon 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5

Open the chart page →

1,672
opencloudunxwaresVerified publisher0.2.32 of 13See more

opencloud unxwares 0.2.3

2 of the 13 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
github.com/go-jose/go-jose/v4@v4.1.0
4.1.4
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.0.5
3.0.5
4.1.4

Open the chart page →

45,392
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
github.com/go-jose/go-jose/v4@v4.1.3
4.1.4

Open the chart page →

696
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

1,114
ciliumvks-helm-chartsVerified publisher1.17.141 of 3See more

cilium vks-helm-charts 1.17.14

1 of the 3 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
quay.io/cilium/operator-generic:v1.17.14773886ec9337
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

4,124
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5

Open the chart page →

6,272
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-jose/go-jose/v3@v3.0.4
github.com/go-jose/go-jose/v4@v4.1.0
3.0.5
4.1.4

Open the chart page →

969
wexa-studiowexa-studio1.2.04 of 15See more

wexa-studio wexa-studio 1.2.0

4 of the 15 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
3.0.5
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
temporalio/server:1.29.1c1e3326b2ce1
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
temporalio/ui:2.44.00b36e00aad30
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

14,618
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4

Open the chart page →

1,187
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-34986.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/go-jose/go-jose/v3@v3.0.3
3.0.5

Open the chart page →

9,381

Container images carrying it

405 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/seamware/did-helper:0.6.0799c5f566952
github.com/go-jose/go-jose/v3@v3.0.1-0.20221117193127-916db76e8214
3.0.5
1
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/go-jose/go-jose/v3@v3.0.0
3.0.5
1
quay.io/thanos/thanos:v0.40.1aae7b2b030ed
github.com/go-jose/go-jose/v4@v4.0.5
4.1.4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
github.com/go-jose/go-jose/v4@v4.1.3
4.1.4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
github.com/go-jose/go-jose/v4@v4.1.3
4.1.4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.