{"api_version":"v1","generated_at":"2026-10-09T19:20:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-go-jose-go-jose-c1aa13657676","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"go-jose","next_cursor":null,"observations":[{"affected":"go-jose: >= 4.0.0, < 4.1.4, < 3.0.5","affected_versions_present":true,"cve_id":"CVE-2026-34986","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34986","fixed":"RHSA-2026:65906: Red Hat OpenShift Container Platform 4.12","last_modified":"2026-09-18T12:04:40.279Z","patch_url":"https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8","primary_source":"","published":"2026-04-06T16:22:45.353Z"},{"affected":">= 4.0.0, < 4.0.5","affected_versions_present":true,"cve_id":"CVE-2025-27144","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27144","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-02-25T14:27:04.978Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-27144","primary_source":"","published":"2025-02-24T22:22:22.863Z"},{"affected":"< 4.0.1; < 3.0.3; < 2.6.3","affected_versions_present":true,"cve_id":"CVE-2024-28180","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28180","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:47:27.104Z","patch_url":"https://github.com/go-jose/go-jose/commit/0dd4dd541c665fb292d664f77604ba694726f298","primary_source":"","published":"2024-03-09T00:54:46.382Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"go-jose"}}
