Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.
CVSS Details
- CVSS 4.0 Base Score: 6.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade skopeo-testsUpgrade skopeoUpgrade buildahUpgrade buildah-tests | May 22, 2025 | Feb 24, 2025 |
| Amazon Linux Ami 2 | — | Upgrade nerdctlUpgrade runfinch-finchUpgrade containerd-stressUpgrade nerdctl-debuginfoUpgrade containerd-debuginfoUpgrade containerd | Apr 2, 2025 | Feb 24, 2025 |
| Amazon_linux_2023 | — | Upgrade containerd-debugsourceUpgrade containerd-stress-debuginfoUpgrade containerdUpgrade containerd-debuginfoUpgrade runfinch-finchUpgrade nerdctlUpgrade containerd-stress | Apr 2, 2025 | Feb 24, 2025 |
| Debian | — | Upgrade golang-github-go-jose-go-jose | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade podman-testsUpgrade osbuild-composer-coreUpgrade podman-pluginsUpgrade skopeo-testsUpgrade buildahUpgrade skopeoUpgrade podman-remoteUpgrade osbuild-composerUpgrade osbuild-composer-workerUpgrade podman-dockerUpgrade podmanUpgrade buildah-tests | May 26, 2025 | Feb 24, 2025 |
| Redhat Openshift | — | Upgrade rhcosUpgrade podmanUpgrade skopeo | Mar 26, 2025 | Feb 24, 2025 |
| Redhat_linux | — | Upgrade buildah-debugsourceUpgrade osbuild-composer-worker-debuginfoUpgrade podman-pluginsUpgrade skopeo-testsUpgrade podman-debugsourceUpgrade podman-remote-debuginfoUpgrade podmanUpgrade osbuild-composer-workerUpgrade osbuild-composer-debugsourceUpgrade podman-testsUpgrade skopeoUpgrade opentelemetry-collectorUpgrade buildah-testsUpgrade osbuild-composer-coreUpgrade skopeo-debuginfoUpgrade osbuild-composer-tests-debuginfoUpgrade osbuild-composer-debuginfoUpgrade podman-dockerUpgrade skopeo-debugsourceUpgrade podman-debuginfoUpgrade osbuild-composerUpgrade podman-tests-debuginfoUpgrade osbuild-composer-core-debuginfoUpgrade buildahUpgrade podman-plugins-debuginfoUpgrade buildah-tests-debuginfoUpgrade podman-remoteUpgrade buildah-debuginfo | Mar 28, 2025 | Feb 24, 2025 |
| Rocky_linux | — | Upgrade podmanUpgrade podman-pluginsUpgrade podman-debugsourceUpgrade podman-testsUpgrade buildah-debugsourceUpgrade podman-tests-debuginfoUpgrade skopeoUpgrade skopeo-debuginfoUpgrade skopeo-testsUpgrade podman-remoteUpgrade podman-remote-debuginfoUpgrade podman-debuginfoUpgrade skopeo-debugsourceUpgrade buildah-testsUpgrade opentelemetry-collectorUpgrade buildah-tests-debuginfoUpgrade buildah-debuginfoUpgrade buildahUpgrade podman-plugins-debuginfo | Oct 6, 2025 | Oct 3, 2025 |
| Suse | — | Upgrade apptainer-sle15_5Upgrade podmanshUpgrade podmanUpgrade buildahUpgrade apptainer-leapUpgrade cosign-zsh-completionUpgrade trivyUpgrade cosignUpgrade skopeoUpgrade cosign-bash-completionUpgrade skopeo-fish-completionUpgrade rekorUpgrade apptainerUpgrade apptainer-sle15_6Upgrade skopeo-zsh-completionUpgrade govulncheck-vulndbUpgrade podman-remoteUpgrade skopeo-bash-completionUpgrade grafanaUpgrade podman-docker | Dec 5, 2025 | Jun 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub