Security advisories
Last updated: 3 September 2026
Vulnerabilities fixed in Daemez products, published once the update is available to customers — the public disclosure required of us as manufacturer (Cyber Resilience Act, Annex I Part II (4)). Report a vulnerability: security@daemez.com · vulnerability disclosure policy. Machine-readable assessments (which findings do not affect our products, and why): VEX for iTraze.
| Date | Product | CVE | Severity | Component | Affected | Fixed in |
|---|---|---|---|---|---|---|
| 2026-09-03 | iTraze | CVE-2025-30204 | High (8.7) | github.com/golang-jwt/jwt v4 | up to and including 0.84.1 | 0.84.3 |
| 2026-09-03 | iTraze | CVE-2026-84304 | High | google.golang.org/grpc | up to and including 0.84.2 | 0.84.3 |
| 2026-09-03 | iTraze | CVE-2026-54063 | High | github.com/xuri/excelize/v2 | up to and including 0.84.2 | 0.84.3 |
| 2026-09-03 | iTraze | CVE-2026-56854 | High | golang.org/x/crypto | up to and including 0.84.1 | 0.84.3 |
| 2026-09-03 | iTraze | CVE-2020-26160 | High | github.com/dgrijalva/jwt-go | up to and including 0.84.1 | 0.84.3 |
CVE-2025-30204 is the one that was reachable without authentication: a crafted token could make the server consume excessive memory while parsing it, before any credential check — a denial of service. It does not allow access to data or execution of code, and we have no indication of exploitation against any customer. The other four were present in the shipped software but not reachable on any code path we execute; they were removed by upgrading the libraries.
Customers running iTraze receive these notices directly and download updates from the customer portal. Updates are free of charge for licensed installations.