Junglewise Threat Intelligence

CVE-2024-28122: GO-2024-2632 - JWX vulnerable to a denial of service attack using compressed JWE message in github.com/lestrrat-go/jwx

CVE-2024-28122 · Severity: low · CVSS 3.1 · Published 2024-05-20

Technologies: github.com/lestrrat-go/jwx/v2 (Go), github.com/lestrrat-go/jwx (Go). Vendors: Go.

Executive brief

JWX vulnerable to a denial of service attack using compressed JWE message in github.com/lestrrat-go/jwx

Affected products

  • Go github.com/lestrrat-go/jwx/v2
  • Go github.com/lestrrat-go/jwx

Related threats