github.com/dvsekhvalnov/jose2go
Golang (GO) implementation of Javascript Object Signing and Encryption specification
Activity
- Latest release
- 6d ago
- Total releases
- 6
- Cadence
- ~7 months
- Last 12 months
- 2
Reach
- Stars
- 186
Details
- First release
- Oct 01, 2020
| Version | Released | |
|---|---|---|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (1)
|
|
v1.10.0
minor
|
v1.10.0
minor
Dependencies (1)
|
|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (1)
|
|
v1.7.0
minor
|
v1.7.0
minor
Dependencies (1)
|
|
v1.6.0
minor
1 CVE
CVE-2025-63811
GO-2025-4123
GHSA-9mj6-hxhv-w67j
Nov 18, 2025
Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token high compression ratio in github.com/dvsekhvalnov/jose2go Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token high compression ratio in github.com/dvsekhvalnov/jose2go Fixed in
1.7.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (1)
|
|
v1.5.0
initial
2 CVEs
CVE-2025-63811
GO-2025-4123
GHSA-9mj6-hxhv-w67j
Nov 18, 2025
Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token high compression ratio in github.com/dvsekhvalnov/jose2go Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token high compression ratio in github.com/dvsekhvalnov/jose2go Fixed in
1.7.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50658
GHSA-6294-6rgp-fr7r
GHSA-mhpq-9638-x6pw
GO-2023-2409
Feb 29, 2024
jose2go vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. Fixed in
1.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.5.0
initial
Dependencies (1)
|