CVE-2024-28122: Lestrrat-Go Jwx
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. This issue has been patched in versions 1.2.29 and 2.0.21.
Affected products
- Lestrrat-Go Jwx: before 1.2.29 (fixed in 1.2.29); from 2.0.0, before 2.0.21 (fixed in 2.0.21)
Published 2024-03-09. Last modified 2026-06-17.