GHSA-2c7c-3mj9-8fqh
UNKNOWNThe go-jose package is subject to a "billion hashes attack" causing denial-of-service when decrypting JWE inputs. This occurs when an attacker can provide a PBES2 encrypted JWE blob with a very large p2c value that, when decrypted, produces a denial-of-service.
- Affected
- >=0, <3.0.1, >=0
- Fixed in
- 2.6.2
- Published
- 2023-11-21
- Source
- github