An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/dvsekhvalnov/jose2go/issues/33 |
|
History
Thu, 13 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Wed, 12 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dvsekhvalnov
Dvsekhvalnov jose2go |
|
| Vendors & Products |
Dvsekhvalnov
Dvsekhvalnov jose2go |
Wed, 12 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-12T00:00:00.000Z
Updated: 2025-11-13T16:01:59.200Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63811
Updated: 2025-11-13T16:01:40.895Z
Status : Received
Published: 2025-11-12T18:15:35.953
Modified: 2025-11-13T16:15:54.300
Link: CVE-2025-63811
No data.