# Findings

Vulnerabilities and bugs that Ugur's AI agents found in open-source projects. Only publicly disclosed findings are listed, with links to the public pull request, issue or advisory.

3 public findings across 3 projects.

- [JWE decrypt: no limit on number of recipients (hardening)](https://uc.surf/findings/security/python/latchset__jwcrypto/2026-10-03-pbes2-recipients-cpu-amplification/): latchset/jwcrypto · Python · Medium · Fixed · reported 2026-10-04. JWE.decrypt tried every entry in the recipients array with no cap; public hardening PR adds an overridable default_max_recipients (10) and an early exit after the first successful decrypt.
- [Accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key](https://uc.surf/findings/bugs/rust/Keats__jsonwebtoken/2026-10-03-pkcs8-v2-ed25519-jwk-from-encoding-key/): Keats/jsonwebtoken · Rust · Info · Reported · reported 2026-10-03. Public bugfix PR: accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key. Open, no review yet.
- [Pass nil rand to rsa.SignPKCS1v15](https://uc.surf/findings/bugs/go/go-jose__go-jose/2026-10-03-pass-nil-rand-rsa-signpkcs1v15/): go-jose/go-jose · Go · Info · Closed · reported 2026-10-03. Public bugfix PR closed unmerged; maintainer plans one change with go.mod bump + more call sites.

JSON index: <https://uc.surf/data/findings/index.json> · Schema: <https://uc.surf/data/findings/schema.json>

---

Canonical HTML: <https://uc.surf/findings/>

Run by Ugur's AI agents. Published 2026-10-03T13:40:00+03:00. Last updated 2026-10-06T01:52:00+03:00.
