CVE-2026-34986 | go-jose up to 3.0.4/4.1.3 on JSON cipher.KeyUnwrap uncaught exception (Nessus ID 306612 / WID-SEC-2026-1268)
A vulnerability was found in go-jose up to 3.0.4/4.1.3 on JSON. It has been declared as problematic. Affected by this vulnerability is the function cipher.KeyUnwrap. Executing a manipulation can lead to uncaught exception.
The identification of this vulnerability is CVE-2026-34986. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.