jose
JSON Object Signing and Encryption (JOSE) for Erlang and Elixir.
Activity
- Latest release
- 9mo ago
- Total releases
- 46
- Cadence
- ~9 days
- Last 12 months
- 2
Details
- License
- MIT
- First release
- Aug 06, 2015
| Version | Released | |
|---|---|---|
1.11.12
patch
|
1.11.12
patch
|
|
1.11.11
patch
|
1.11.11
patch
|
|
1.11.10
patch
|
1.11.10
patch
|
|
1.11.9
patch
|
1.11.9
patch
|
|
1.11.8
patch
|
1.11.8
patch
Dependencies (2)
|
|
1.11.7
patch
|
1.11.7
patch
Dependencies (2)
|
|
1.11.6
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.11.6
patch
|
|
1.11.5
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.11.5
patch
|
|
1.11.4
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.11.4
patch
|
|
1.11.2
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.11.2
patch
|
|
1.11.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.11.1
patch
|
|
1.11.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.11.0
minor
|
|
1.10.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.10.1
patch
|
|
1.10.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.10.0
minor
|
|
1.9.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.9.0
minor
Dependencies (1)
|
|
1.8.4
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.8.4
patch
Dependencies (1)
|
|
1.8.3
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.8.3
patch
Dependencies (1)
|
|
1.8.2
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.8.2
patch
Dependencies (1)
|
|
1.8.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.8.1
patch
Dependencies (1)
|
|
1.8.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.8.0
minor
Dependencies (1)
|
|
1.7.9
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.9
patch
Dependencies (1)
|
|
1.7.8
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.8
patch
Dependencies (1)
|
|
1.7.7
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.7
patch
Dependencies (1)
|
|
1.7.6
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.6
patch
Dependencies (1)
|
|
1.7.5
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.5
patch
Dependencies (1)
|
|
1.7.4
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.4
patch
Dependencies (1)
|
|
1.7.3
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.3
patch
Dependencies (1)
|
|
1.7.2
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.2
patch
Dependencies (1)
|
|
1.7.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.1
patch
Dependencies (1)
|
|
1.7.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.7.0
minor
Dependencies (1)
|
|
1.6.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.6.1
patch
Dependencies (1)
|
|
1.6.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.6.0
minor
Dependencies (1)
|
|
1.5.2
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.5.2
patch
Dependencies (1)
|
|
1.5.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.5.1
patch
Dependencies (1)
|
|
1.5.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.5.0
minor
Dependencies (1)
|
|
1.4.2
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.4.2
patch
Dependencies (1)
|
|
1.4.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.4.1
patch
Dependencies (1)
|
|
1.4.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.4.0
minor
Dependencies (1)
|
|
1.3.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.3.0
minor
Dependencies (1)
|
|
1.2.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.2.0
minor
Dependencies (1)
|
|
1.1.3
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.1.3
patch
Dependencies (2)
|
|
1.1.2
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.1.2
patch
Dependencies (2)
|
|
1.1.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.1.1
patch
Dependencies (2)
|
|
1.1.0
minor
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.1.0
minor
Dependencies (2)
|
|
1.0.1
patch
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.0.1
patch
Dependencies (2)
|
|
1.0.0
initial
1 CVE
CVE-2023-50966
GHSA-9mg4-v392-8j68
Mar 19, 2024
erlang-jose vulnerable to denial of service via large p2c value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.4
+ 28 more Show less
1.11.5
1.11.6
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
Fixed in
1.11.7
References Updated Dec 10, 2025 · Source: OSV.dev |
1.0.0
initial
Dependencies (1)
|