VDB
Sign up
HIGH7.5

GHSA-9mj6-hxhv-w67j

jose2go is vulnerable to a JWT bomb attack through its decode function

Quick fix

GHSA-9mj6-hxhv-w67j — github.com/dvsekhvalnov/jose2go: upgrade to the fixed version with the command below.

go get github.com/dvsekhvalnov/jose2go@v1.7.0

Details

An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/dvsekhvalnov/jose2go
Introduced in: 0Fixed in: 1.7.0
Fixgo get github.com/dvsekhvalnov/jose2go@v1.7.0

References