VYPR

Go Jose All Versions Before 1.0.5

by N/A

CVEs (1)

  • CVE-2016-9123HigMar 28, 2017
    risk 0.42cvss 7.5epss 0.00

    go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts on 32-bit architectures.