{
  "generated_at": "2026-10-05T22:53:05+00:00",
  "count": 3,
  "public_count": 3,
  "schema": "https://uc.surf/data/findings/schema.json",
  "findings": [
    {
      "id": "security/python/latchset__jwcrypto/2026-10-03-pbes2-recipients-cpu-amplification",
      "path": "security/python/latchset__jwcrypto/2026-10-03-pbes2-recipients-cpu-amplification.json",
      "url": "https://uc.surf/findings/security/python/latchset__jwcrypto/2026-10-03-pbes2-recipients-cpu-amplification/",
      "json_url": "https://uc.surf/data/findings/security/python/latchset__jwcrypto/2026-10-03-pbes2-recipients-cpu-amplification.json",
      "title": "JWE decrypt: no limit on number of recipients (hardening)",
      "category": "security",
      "severity": "medium",
      "status": "fixed",
      "public": true,
      "ecosystem": "python",
      "project": {
        "owner": "latchset",
        "repo": "jwcrypto",
        "url": "https://github.com/latchset/jwcrypto"
      },
      "summary": "JWE.decrypt tried every entry in the recipients array with no cap; public hardening PR adds an overridable default_max_recipients (10) and an early exit after the first successful decrypt.",
      "disclosed_at": "2026-10-04T00:00:00+03:00",
      "updated_at": "2026-10-06T01:52:00+03:00"
    },
    {
      "id": "bugs/rust/Keats__jsonwebtoken/2026-10-03-pkcs8-v2-ed25519-jwk-from-encoding-key",
      "path": "bugs/rust/Keats__jsonwebtoken/2026-10-03-pkcs8-v2-ed25519-jwk-from-encoding-key.json",
      "url": "https://uc.surf/findings/bugs/rust/Keats__jsonwebtoken/2026-10-03-pkcs8-v2-ed25519-jwk-from-encoding-key/",
      "json_url": "https://uc.surf/data/findings/bugs/rust/Keats__jsonwebtoken/2026-10-03-pkcs8-v2-ed25519-jwk-from-encoding-key.json",
      "title": "Accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key",
      "category": "bugs",
      "severity": "info",
      "status": "reported",
      "public": true,
      "ecosystem": "rust",
      "project": {
        "owner": "Keats",
        "repo": "jsonwebtoken",
        "url": "https://github.com/Keats/jsonwebtoken"
      },
      "summary": "Public bugfix PR: accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key. Open, no review yet.",
      "disclosed_at": "2026-10-03T23:08:17+03:00",
      "updated_at": "2026-10-05T09:59:00+03:00"
    },
    {
      "id": "bugs/go/go-jose__go-jose/2026-10-03-pass-nil-rand-rsa-signpkcs1v15",
      "path": "bugs/go/go-jose__go-jose/2026-10-03-pass-nil-rand-rsa-signpkcs1v15.json",
      "url": "https://uc.surf/findings/bugs/go/go-jose__go-jose/2026-10-03-pass-nil-rand-rsa-signpkcs1v15/",
      "json_url": "https://uc.surf/data/findings/bugs/go/go-jose__go-jose/2026-10-03-pass-nil-rand-rsa-signpkcs1v15.json",
      "title": "Pass nil rand to rsa.SignPKCS1v15",
      "category": "bugs",
      "severity": "info",
      "status": "closed",
      "public": true,
      "ecosystem": "go",
      "project": {
        "owner": "go-jose",
        "repo": "go-jose",
        "url": "https://github.com/go-jose/go-jose"
      },
      "summary": "Public bugfix PR closed unmerged; maintainer plans one change with go.mod bump + more call sites.",
      "disclosed_at": "2026-10-03T23:04:49+03:00",
      "updated_at": "2026-10-05T09:59:00+03:00"
    }
  ]
}
