Skip to content
daemez
  • Home
  • Products
  • Integrations
Contact

Security advisories

Last updated: 3 September 2026


Vulnerabilities fixed in Daemez products, published once the update is available to customers — the public disclosure required of us as manufacturer (Cyber Resilience Act, Annex I Part II (4)). Report a vulnerability: security@daemez.com · vulnerability disclosure policy. Machine-readable assessments (which findings do not affect our products, and why): VEX for iTraze.

Date Product CVE Severity Component Affected Fixed in
2026-09-03 iTraze CVE-2025-30204 High (8.7) github.com/golang-jwt/jwt v4 up to and including 0.84.1 0.84.3
2026-09-03 iTraze CVE-2026-84304 High google.golang.org/grpc up to and including 0.84.2 0.84.3
2026-09-03 iTraze CVE-2026-54063 High github.com/xuri/excelize/v2 up to and including 0.84.2 0.84.3
2026-09-03 iTraze CVE-2026-56854 High golang.org/x/crypto up to and including 0.84.1 0.84.3
2026-09-03 iTraze CVE-2020-26160 High github.com/dgrijalva/jwt-go up to and including 0.84.1 0.84.3

CVE-2025-30204 is the one that was reachable without authentication: a crafted token could make the server consume excessive memory while parsing it, before any credential check — a denial of service. It does not allow access to data or execution of code, and we have no indication of exploitation against any customer. The other four were present in the shipped software but not reachable on any code path we execute; they were removed by upgrading the libraries.

Customers running iTraze receive these notices directly and download updates from the customer portal. Updates are free of charge for licensed installations.


daemez
Legal noticeTerms of usePrivacyCookiesAccessibility

© 2026 DAEMEZ SOLUCIONS, S.L.

With your consent we use analytics cookies to measure visits — including whether you come back and which campaign brought you here. The tool is self-hosted; no data leaves our servers. You can change your choice at any time from "Cookie settings" in the footer. Cookie policy