VDB

GO-2025-3376

GO-2025-3376 PUBLISHED

JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh in github.com/MicahParks/jwkset

Affected Products

VendorProductVersions
github.comMicahParks/jwkset0.5.0, 0.5.0

Timeline

  • Jan 9, 2025 CVE Published
  • Mar 3, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›