Skip to content

go-jose v2.6.3 CVE-2025-27144 resolution #739

@cloudxxx8

Description

@cloudxxx8

There is a CVE in go-jose v2.6.3
Our project depends on openziti sdk-golang, so this dependency is included

gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect

Please see more details from the dependabot security adviosry
https://www.mend.io/vulnerability-database/CVE-2025-27144?utm_source=JetBrains

Please see if you can upgrade to the latest go-jose lib in v4
https://github.com/go-jose/go-jose

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions