dvsekhvalnov/jose2go

dvsekhvalnov/jose2go

Releases8
Frequency1 year 4 months
Last Release
Stars189
Golang (GO) implementation of Javascript Object Signing and Encryption specification

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.

7.5 HIGH

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.