Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.
CVSS Details
- CVSS 4.0 Base Score: 6.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade buildahUpgrade buildah-testsUpgrade skopeoUpgrade skopeo-tests | May 22, 2025 | Feb 24, 2025 |
| Amazon Linux Ami 2 | — | Upgrade nerdctl-debuginfoUpgrade containerdUpgrade containerd-debuginfoUpgrade nerdctlUpgrade runfinch-finchUpgrade containerd-stress | Apr 2, 2025 | Feb 24, 2025 |
| Amazon_linux_2023 | — | Upgrade containerd-debugsourceUpgrade containerd-stress-debuginfoUpgrade containerd-stressUpgrade runfinch-finchUpgrade containerdUpgrade containerd-debuginfoUpgrade nerdctl | Apr 2, 2025 | Feb 24, 2025 |
| Debian | — | Upgrade golang-github-go-jose-go-jose | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade skopeoUpgrade podman-remoteUpgrade buildahUpgrade osbuild-composer-workerUpgrade podman-dockerUpgrade buildah-testsUpgrade osbuild-composerUpgrade podmanUpgrade podman-pluginsUpgrade skopeo-testsUpgrade osbuild-composer-coreUpgrade podman-tests | May 26, 2025 | Feb 24, 2025 |
| Redhat Openshift | — | Upgrade skopeoUpgrade podman | Mar 26, 2025 | Feb 24, 2025 |
| Redhat_linux | — | Upgrade skopeo-debugsourceUpgrade buildah-tests-debuginfoUpgrade buildah-testsUpgrade podman-plugins-debuginfoUpgrade osbuild-composer-core-debuginfoUpgrade opentelemetry-collectorUpgrade podman-dockerUpgrade skopeo-debuginfoUpgrade osbuild-composer-tests-debuginfoUpgrade buildah-debuginfoUpgrade osbuild-composer-debuginfoUpgrade podman-remoteUpgrade skopeo-testsUpgrade osbuild-composer-worker-debuginfoUpgrade osbuild-composer-workerUpgrade podmanUpgrade podman-pluginsUpgrade podman-testsUpgrade osbuild-composer-debugsourceUpgrade podman-remote-debuginfoUpgrade buildah-debugsourceUpgrade podman-debugsourceUpgrade skopeoUpgrade podman-tests-debuginfoUpgrade buildahUpgrade osbuild-composer-coreUpgrade podman-debuginfoUpgrade osbuild-composer | Mar 28, 2025 | Feb 24, 2025 |
| Rocky_linux | — | Upgrade skopeo-debuginfoUpgrade skopeo-testsUpgrade podmanUpgrade podman-testsUpgrade podman-debugsourceUpgrade podman-pluginsUpgrade buildah-debugsourceUpgrade podman-tests-debuginfoUpgrade skopeoUpgrade podman-debuginfoUpgrade podman-remote-debuginfoUpgrade skopeo-debugsourceUpgrade buildahUpgrade opentelemetry-collectorUpgrade buildah-tests-debuginfoUpgrade podman-remoteUpgrade buildah-testsUpgrade podman-plugins-debuginfoUpgrade buildah-debuginfo | Oct 6, 2025 | Oct 3, 2025 |
| Suse | — | Upgrade podman-dockerUpgrade skopeo-zsh-completionUpgrade rekorUpgrade skopeo-bash-completionUpgrade skopeo-fish-completionUpgrade podman-remoteUpgrade govulncheck-vulndbUpgrade grafanaUpgrade apptainer-sle15_6Upgrade apptainerUpgrade buildahUpgrade cosign-bash-completionUpgrade trivyUpgrade cosignUpgrade apptainer-sle15_5Upgrade podmanUpgrade skopeoUpgrade cosign-zsh-completionUpgrade podmanshUpgrade apptainer-leap | Dec 5, 2025 | Jun 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub