VDB
Sign up
MEDIUM

GHSA-c6gw-w398-hv78

DoS in go-jose Parsing

Quick fix

GHSA-c6gw-w398-hv78 — github.com/go-jose/go-jose/v4: upgrade to the fixed version with the command below.

go get github.com/go-jose/go-jose/v4@v4.0.5

Details

### Impact When parsing compact JWS or JWE input, go-jose could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of '.' characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service.

### Patches Version 4.0.5 fixes this issue

### Workarounds Applications could pre-validate payloads passed to go-jose do not contain an excessive number of '.' characters.

### References This is the same sort of issue as in the golang.org/x/oauth2/jws package as CVE-2025-22868 and Go issue https://go.dev/issue/71490.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/go-jose/go-jose/v4
Introduced in: 0Fixed in: 4.0.5
Fixgo get github.com/go-jose/go-jose/v4@v4.0.5
Go/github.com/go-jose/go-jose/v3
Introduced in: 0Fixed in: 3.0.4
Fixgo get github.com/go-jose/go-jose/v3@v3.0.4
Go/github.com/go-jose/go-jose
Introduced in: 0Fixed in: 3.0.4
Fixgo get github.com/go-jose/go-jose@v3.0.4

References