Fix available for `CVE-2026-34986` in `go-jose` `v3.0.5`
### Issue Details
Hello! Could you update `go-jose/v3` from `v3.0.4` to `v3.0.5`?
The [v3.0.5 release notes](https://github.com/go-jose/go-jose/releases/tag/v3.0.5) state it fixes [GHSA-78h2-9frx-2jm8](https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8) (CVE-2026-34986), which security scanners are currently flagging.
For reference, [caddyserver/caddy#7621](https://github.com/caddyserver/caddy/pull/7621) applies the equivalent update for `go-jose/v4` (`v4.1.3` → `v4.1.4`).
**Note**: [caddyserver/caddy#7622](https://github.com/caddyserver/caddy/pull/7622) previously attempted this `go-jose/v3` update but was closed.
Thank you!
### Assistance Disclosure
AI used
### If AI was used, describe the extent to which it was used.
Improved formatting and clarity of my original hand-written report
关闭于 2026-05-19 1 条评论