blob: 9b04446adf5a358eeccf301d03930025cb81237c [file] [edit]
id: GO-2026-4769
modules:
- module: github.com/juju/juju
non_go_versions:
- introduced: 3.0.0
- fixed: 3.6.19
vulnerable_at: 0.0.0-20260313152531-78529496d3f7
summary: Juju affected by timing ownership claim attack on new external back-end secrets in github.com/juju/juju
cves:
- CVE-2026-32691
ghsas:
- GHSA-gfgr-6hrj-85ww
references:
- advisory: https://github.com/juju/juju/security/advisories/GHSA-gfgr-6hrj-85ww
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-32691
source:
id: GHSA-gfgr-6hrj-85ww
created: 2026-03-23T12:53:57.393640797-04:00
review_status: UNREVIEWED