GHSA-hj3v-m684-v259
MODERATECVE-2024-28122This vulnerability allows an attacker with a trusted public key to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the recipient, it results in significant memory allocation and processing time during decompression.
- Affected
- < 2.0.21
- Fixed in
- 2.0.21
- Weakness
- CWE-400
- Published
- 2024-03-08
- Source
- github