Vulnerability Report: GO-2024-2631
- CVE-2024-28180, GHSA-c5q2-7r4c-mv6g
- Affects: github.com/go-jose/go-jose/v4, github.com/go-jose/go-jose/v3, and 2 more
- Published: Mar 15, 2024
- Modified: May 20, 2024
An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti.
For detailed information about this vulnerability, visit https://github.com/go-jose/go-jose/security/advisories/GHSA-c5q2-7r4c-mv6g.
Affected Packages
-
PathGo VersionsSymbols
-
before v4.0.1
-
before v3.0.3
-
before v2.6.3
-
all versions, no known fixed
Aliases
References
- https://github.com/go-jose/go-jose/security/advisories/GHSA-c5q2-7r4c-mv6g
- https://github.com/go-jose/go-jose/commit/0dd4dd541c665fb292d664f77604ba694726f298
- https://github.com/go-jose/go-jose/commit/add6a284ea0f844fd6628cba637be5451fe4b28a
- https://github.com/go-jose/go-jose/commit/f4c051a0653d78199a053892f7619ebf96339502
- https://vuln.go.dev/ID/GO-2024-2631.json
Credits
- zer0yu, chenjj
Feedback
See anything missing or incorrect?
Suggest an edit to this report.