VYPR

Go modules package

gopkg.in/go-jose/go-jose.v2

pkg:golang/gopkg.in/go-jose/go-jose.v2

Vulnerabilities (1)

  • CVE-2024-28180Mar 9, 2024
    affected < 2.6.3fixed 2.6.3

    Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now ret