CVE-2023-31582: JOSE4J Project JOSE4J
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
Affected products
- JOSE4J Project JOSE4J: before 0.9.3 (fixed in 0.9.3)
Published 2023-10-25. Last modified 2026-06-17.