CVE-2025-63811: Dvsekhvalnov JOSE2GO
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.
Affected products
- Dvsekhvalnov JOSE2GO: from 1.5.0, before 1.7.0 (fixed in 1.7.0)
Published 2025-11-12. Last modified 2026-06-17.