HIGH7.5
GHSA-9mj6-hxhv-w67j
jose2go is vulnerable to a JWT bomb attack through its decode function
Quick fix
GHSA-9mj6-hxhv-w67j — github.com/dvsekhvalnov/jose2go: upgrade to the fixed version with the command below.
go get github.com/dvsekhvalnov/jose2go@v1.7.0Details
An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/dvsekhvalnov/jose2go
Introduced in:
0Fixed in: 1.7.0Fix
go get github.com/dvsekhvalnov/jose2go@v1.7.0