Improper Handling of Highly Compressed Data (Data Amplification) Affecting gopkg.in/go-jose/go-jose.v2 package, versions <2.6.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GOPKGINGOJOSEGOJOSEV2-6419235
  • published8 Mar 2024
  • disclosed7 Mar 2024
  • creditEnze Wang, Jianjun Chen

Introduced: 7 Mar 2024

CVE-2024-28180  (opens in a new tab)
CWE-409  (opens in a new tab)

How to fix?

Upgrade gopkg.in/go-jose/go-jose.v2 to version 2.6.3 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification). An attacker could send a JWE containing compressed data that, when decompressed by Decrypt or DecryptMulti, would use large amounts of memory and CPU.

CVSS Scores

version 3.1