CVE-2025-45769

php-jwt v6.11.0 was discovered to contain weak...Read More ...

Continue Reading
CVE-2025-45770

jwt v5.4.3 was discovered to contain weak...Read More ...

Continue Reading
Security Bulletin: IBM Financial Transaction Manager is impacted by multiple vulnerabilities in RedHat Proxy for Kubernetes RBAC authorization

Summary IBM Financial Transaction Manager for RedHat OpenShift has addressed the following vulnerabilities. Vulnerability Details CVEID:CVE-2024-45338 DESCRIPTION: An attacker can craft an input to th ...

Continue Reading
Security Bulletin: Multiple vulnerabilities that affect IBM Db2 Intelligence Center (CVE-2025-22869, CVE-2024-45339, CVE-2025-30204)

Summary github.com/golang-JWT/jwt/v4-v4.5.1, github.com/golang/glog-v0.0.0, golang.org/x/crypto-v0.31.0, dependency packages are being used by IBM Db2 Intelligence Center. This bulletin describes the ...

Continue Reading
RLSA-2025:3344 Important: grafana security update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): golang-jwt/jwt: jwt-go allows excessive memory allocation duri ...

Continue Reading
RLSA-2025:3411 Important: opentelemetry-collector security update

Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry Security Fix(es): golang-jwt/jwt: jwt-go allows excessive memory allocation during header par ...

Continue Reading
CVE-2025-45770

jwt v5.4.3 was discovered to contain weak...Read More ...

Continue Reading
CVE-2024-48916

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signat ...

Continue Reading

Back to Main

Subscribe for the latest news: