{"id":"GHSA-2c7c-3mj9-8fqh","aliases":["GO-2023-2334"],"url":"https://o3.security/vulnerability/GHSA-2c7c-3mj9-8fqh","summary":"Decryption of malicious PBES2 JWE objects can consume unbounded system resources","details":"The go-jose package is subject to a \"billion hashes attack\" causing denial-of-service when decrypting JWE inputs. This occurs when an attacker can provide a PBES2 encrypted JWE blob with a very large p2c value that, when decrypted, produces a denial-of-service.","published":"2023-11-21T22:17:19Z","modified":"2026-09-10T03:49:58.719941857Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/go-jose/go-jose/v3","fixedVersion":"3.0.1"},{"ecosystem":"Go","name":"github.com/square/go-jose","fixedVersion":"2.6.2"}],"fix":{"url":"https://github.com/go-jose/go-jose/commit/65351c27657d58960c2e6c9fbb2b00f818e50568","label":"go-jose/go-jose@65351c2"},"references":[{"type":"WEB","url":"https://github.com/go-jose/go-jose/issues/64"},{"type":"WEB","url":"https://github.com/go-jose/go-jose/commit/65351c27657d58960c2e6c9fbb2b00f818e50568"},{"type":"WEB","url":"https://github.com/go-jose/go-jose/commit/a3d307244c3bc50b25a71aa0688764c32ec419c7"},{"type":"PACKAGE","url":"https://github.com/go-jose/go-jose"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:49:58.719941857Z"}}