JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. This issue has been patched in versions 1.2.29 and 2.0.21.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lestrrat-go
Lestrrat-go jwx |
|
CPEs | cpe:2.3:a:lestrrat-go:jwx:1.2.0:*:*:*:*:*:*:* cpe:2.3:a:lestrrat-go:jwx:2.0.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Lestrrat-go
Lestrrat-go jwx |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-16T15:49:42.161Z
Reserved: 2024-03-04T14:19:14.060Z
Link: CVE-2024-28122

Updated: 2024-08-02T00:48:48.987Z

Status : Awaiting Analysis
Published: 2024-03-09T01:15:06.940
Modified: 2024-11-21T09:05:51.847
Link: CVE-2024-28122
