Skip to content

CVE-2025-47913 & CVE-2026-34986 #409

Description

@askmike1

The library golang.org/x/crypto version 0.40.0 was detected in envconsul and is vulnerable to CVE-2025-47913, which exists in versions < 0.43.0.

⁠The library github.com/go-jose/go-jose/v4 version 4.1.1 was detected in envconsul and is vulnerable to CVE-2026-34986, which exists in versions < 4.1.4.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions