Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.
CVSS Details
- CVSS 4.0 Base Score: 6.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade skopeo-testsUpgrade skopeoUpgrade buildahUpgrade buildah-tests | May 22, 2025 | Feb 24, 2025 |
| Amazon Linux Ami 2 | — | Upgrade runfinch-finchUpgrade containerd-stressUpgrade nerdctlUpgrade containerd-debuginfoUpgrade nerdctl-debuginfoUpgrade containerd | Apr 2, 2025 | Feb 24, 2025 |
| Amazon_linux_2023 | — | Upgrade containerd-debuginfoUpgrade runfinch-finchUpgrade containerd-stressUpgrade containerdUpgrade nerdctlUpgrade containerd-debugsourceUpgrade containerd-stress-debuginfo | Apr 2, 2025 | Feb 24, 2025 |
| Debian | — | Upgrade golang-github-go-jose-go-jose | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade osbuild-composerUpgrade osbuild-composer-workerUpgrade podman-dockerUpgrade podmanUpgrade podman-remoteUpgrade skopeoUpgrade buildahUpgrade buildah-testsUpgrade osbuild-composer-coreUpgrade podman-testsUpgrade podman-pluginsUpgrade skopeo-tests | May 26, 2025 | Feb 24, 2025 |
| Redhat Openshift | — | Upgrade podmanUpgrade skopeoUpgrade rhcos | Mar 26, 2025 | Feb 24, 2025 |
| Redhat_linux | — | Upgrade opentelemetry-collectorUpgrade osbuild-composer-core-debuginfoUpgrade buildah-testsUpgrade podman-dockerUpgrade podman-remoteUpgrade podman-debuginfoUpgrade osbuild-composer-debuginfoUpgrade podman-tests-debuginfoUpgrade buildah-debuginfoUpgrade osbuild-composer-coreUpgrade osbuild-composerUpgrade buildahUpgrade skopeo-debuginfoUpgrade buildah-tests-debuginfoUpgrade osbuild-composer-tests-debuginfoUpgrade podman-plugins-debuginfoUpgrade skopeo-debugsourceUpgrade podman-remote-debuginfoUpgrade osbuild-composer-worker-debuginfoUpgrade skopeoUpgrade podman-testsUpgrade podmanUpgrade buildah-debugsourceUpgrade podman-debugsourceUpgrade podman-pluginsUpgrade osbuild-composer-debugsourceUpgrade osbuild-composer-workerUpgrade skopeo-tests | Mar 28, 2025 | Feb 24, 2025 |
| Rocky_linux | — | Upgrade buildah-debuginfoUpgrade skopeo-debugsourceUpgrade buildah-tests-debuginfoUpgrade buildah-testsUpgrade podman-plugins-debuginfoUpgrade opentelemetry-collectorUpgrade podman-remoteUpgrade buildahUpgrade podman-debuginfoUpgrade podman-remote-debuginfoUpgrade skopeo-debuginfoUpgrade podmanUpgrade podman-tests-debuginfoUpgrade skopeo-testsUpgrade skopeoUpgrade podman-pluginsUpgrade podman-debugsourceUpgrade podman-testsUpgrade buildah-debugsource | Oct 6, 2025 | Oct 3, 2025 |
| Suse | — | Upgrade cosign-zsh-completionUpgrade apptainer-sle15_5Upgrade buildahUpgrade cosignUpgrade trivyUpgrade apptainer-leapUpgrade skopeoUpgrade podmanUpgrade cosign-bash-completionUpgrade podmanshUpgrade govulncheck-vulndbUpgrade podman-dockerUpgrade grafanaUpgrade apptainer-sle15_6Upgrade podman-remoteUpgrade skopeo-bash-completionUpgrade rekorUpgrade skopeo-fish-completionUpgrade apptainerUpgrade skopeo-zsh-completion | Dec 5, 2025 | Jun 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub