GHSA-2c7c-3mj9-8fqh
ADVISORY - githubSummary
The go-jose package is subject to a "billion hashes attack" causing denial-of-service when decrypting JWE inputs. This occurs when an attacker can provide a PBES2 encrypted JWE blob with a very large p2c value that, when decrypted, produces a denial-of-service.
Common Weakness Enumeration (CWE)
Uncontrolled Resource Consumption
GitHub
-
CVSS SCORE
N/AmediumGoLang
-
Chainguard
CGA-257w-7h7q-82qg
-
Chainguard
CGA-2x27-gh6f-f9vx
-
Chainguard
CGA-34h5-5pxj-hvrw
-
Chainguard
CGA-3776-mx8v-8579
-
Chainguard
CGA-383f-p5v3-66vf
-
Chainguard
CGA-539g-23xp-crcp
-
Chainguard
CGA-5jmc-x3w7-39j5
-
Chainguard
CGA-5w5v-75p5-6p47
-
Chainguard
CGA-6933-x86j-v4cp
-
Chainguard
CGA-6j54-9gxf-4r4g
-
Chainguard
CGA-6m42-fhwp-4p75
-
Chainguard
CGA-6qwr-287m-r6c9
-
Chainguard
CGA-76mm-qr6r-q942
-
Chainguard
CGA-7g7c-22jg-fj99
-
Chainguard
CGA-7qvp-4pvh-v368
-
Chainguard
CGA-8fc8-wj82-33f5
-
Chainguard
CGA-8ww6-7wwv-g3pc
-
Chainguard
CGA-95fj-w5w4-65hh
-
Chainguard
CGA-c58f-9j9v-q44m
-
Chainguard
CGA-f3vh-f4mj-jr28
-
Chainguard
CGA-f54x-xrpq-qmc5
-
Chainguard
CGA-fm2r-q69f-j8r4
-
Chainguard
CGA-hj78-mwp5-p9jh
-
Chainguard
CGA-hr25-7rwf-rrm7
-
Chainguard
CGA-hvcf-hfwc-22rr
-
Chainguard
CGA-jf6q-6mqf-hc2g
-
Chainguard
CGA-jhxm-cvq3-9g9v
-
Chainguard
CGA-jprv-637x-8rwx
-
Chainguard
CGA-m53g-c749-fg6f
-
Chainguard
CGA-mg2v-gvq6-q64m
-
Chainguard
CGA-pf27-r5q5-mppm
-
Chainguard
CGA-pfcp-4vfr-fm8q
-
Chainguard
CGA-prgv-h48j-jvq5
-
Chainguard
CGA-q7xw-32f3-28m2
-
Chainguard
CGA-qgc3-83v8-8jg6
-
Chainguard
CGA-qhgx-8825-vc32
-
Chainguard
CGA-qp4q-xr3j-q6cm
-
Chainguard
CGA-qw38-mv85-36vx
-
Chainguard
CGA-r255-c833-5j7m
-
Chainguard
CGA-r8ww-4x3r-m7vw
-
Chainguard
CGA-rggv-pw33-fwwx
-
Chainguard
CGA-v668-vm2q-rh5j
-
Chainguard
CGA-vj23-q6wr-55q7
-
Chainguard
CGA-vmcx-qmfx-qf2h
-
Chainguard
CGA-x3hf-w53m-q3f8
-
Chainguard
CGA-x3vf-hfhh-fph3
-
Chainguard
CGA-x8mg-m7wq-3wxg
-