Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.
CVSS Details
- CVSS 4.0 Base Score: 6.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade skopeo-testsUpgrade buildah-testsUpgrade buildahUpgrade skopeo | May 22, 2025 | Feb 24, 2025 |
| Amazon Linux Ami 2 | — | Upgrade containerd-stressUpgrade runfinch-finchUpgrade nerdctlUpgrade containerdUpgrade nerdctl-debuginfoUpgrade containerd-debuginfo | Apr 2, 2025 | Feb 24, 2025 |
| Amazon_linux_2023 | — | Upgrade containerd-debugsourceUpgrade containerd-stress-debuginfoUpgrade nerdctlUpgrade containerdUpgrade containerd-debuginfoUpgrade containerd-stressUpgrade runfinch-finch | Apr 2, 2025 | Feb 24, 2025 |
| Debian | — | Upgrade golang-github-go-jose-go-jose | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade osbuild-composerUpgrade podman-remoteUpgrade podmanUpgrade buildahUpgrade osbuild-composer-workerUpgrade podman-dockerUpgrade skopeoUpgrade buildah-testsUpgrade podman-testsUpgrade osbuild-composer-coreUpgrade podman-pluginsUpgrade skopeo-tests | May 26, 2025 | Feb 24, 2025 |
| Redhat Openshift | — | Upgrade skopeoUpgrade podmanUpgrade rhcos | Mar 26, 2025 | Feb 24, 2025 |
| Redhat_linux | — | Upgrade podman-dockerUpgrade opentelemetry-collectorUpgrade osbuild-composer-tests-debuginfoUpgrade buildahUpgrade podman-plugins-debuginfoUpgrade buildah-testsUpgrade skopeo-debuginfoUpgrade podman-tests-debuginfoUpgrade podman-debuginfoUpgrade osbuild-composer-core-debuginfoUpgrade osbuild-composerUpgrade skopeo-debugsourceUpgrade podman-remoteUpgrade buildah-tests-debuginfoUpgrade osbuild-composer-coreUpgrade buildah-debuginfoUpgrade osbuild-composer-debuginfoUpgrade podman-remote-debuginfoUpgrade podman-debugsourceUpgrade podman-testsUpgrade skopeoUpgrade podman-pluginsUpgrade podmanUpgrade osbuild-composer-workerUpgrade buildah-debugsourceUpgrade osbuild-composer-debugsourceUpgrade skopeo-testsUpgrade osbuild-composer-worker-debuginfo | Mar 28, 2025 | Feb 24, 2025 |
| Rocky_linux | — | Upgrade buildah-debuginfoUpgrade opentelemetry-collectorUpgrade podman-plugins-debuginfoUpgrade podman-remoteUpgrade podman-remote-debuginfoUpgrade buildah-testsUpgrade podman-debuginfoUpgrade buildah-tests-debuginfoUpgrade buildahUpgrade skopeo-debugsourceUpgrade podman-testsUpgrade skopeoUpgrade buildah-debugsourceUpgrade skopeo-testsUpgrade podman-tests-debuginfoUpgrade podmanUpgrade podman-pluginsUpgrade skopeo-debuginfoUpgrade podman-debugsource | Oct 6, 2025 | Oct 3, 2025 |
| Suse | — | Upgrade skopeo-fish-completionUpgrade apptainerUpgrade rekorUpgrade govulncheck-vulndbUpgrade skopeo-zsh-completionUpgrade apptainer-sle15_6Upgrade podman-dockerUpgrade grafanaUpgrade podman-remoteUpgrade skopeo-bash-completionUpgrade buildahUpgrade cosign-bash-completionUpgrade podmanshUpgrade apptainer-sle15_5Upgrade skopeoUpgrade podmanUpgrade trivyUpgrade cosignUpgrade apptainer-leapUpgrade cosign-zsh-completion | Dec 5, 2025 | Jun 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub