{"schema_version":"1.7.3","id":"GO-2024-2631","published":"2024-03-15T18:16:11Z","modified":"2026-02-04T02:26:19.701630Z","aliases":["CVE-2024-28180","GHSA-c5q2-7r4c-mv6g"],"related":["CGA-44jx-9wpc-p5mm"],"summary":"Decompression bomb vulnerability in github.com/go-jose/go-jose","details":"An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti.","affected":[{"package":{"name":"github.com/go-jose/go-jose/v4","ecosystem":"Go","purl":"pkg:golang/github.com/go-jose/go-jose/v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.0.1"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/go-jose/go-jose/v4","symbols":["JSONWebEncryption.Decrypt","JSONWebEncryption.DecryptMulti","inflate"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2631.json"}},{"package":{"name":"github.com/go-jose/go-jose/v3","ecosystem":"Go","purl":"pkg:golang/github.com/go-jose/go-jose/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.3"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/go-jose/go-jose/v3","symbols":["JSONWebEncryption.Decrypt","JSONWebEncryption.DecryptMulti","inflate"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2631.json"}},{"package":{"name":"gopkg.in/go-jose/go-jose.v2","ecosystem":"Go","purl":"pkg:golang/gopkg.in/go-jose/go-jose.v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.3"}]}],"ecosystem_specific":{"imports":[{"path":"gopkg.in/go-jose/go-jose.v2","symbols":["JSONWebEncryption.Decrypt","JSONWebEncryption.DecryptMulti","inflate"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2631.json"}},{"package":{"name":"gopkg.in/square/go-jose.v2","ecosystem":"Go","purl":"pkg:golang/gopkg.in/square/go-jose.v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{"imports":[{"path":"gopkg.in/square/go-jose.v2","symbols":["JSONWebEncryption.Decrypt","JSONWebEncryption.DecryptMulti","inflate"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2631.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/go-jose/go-jose/security/advisories/GHSA-c5q2-7r4c-mv6g"},{"type":"FIX","url":"https://github.com/go-jose/go-jose/commit/0dd4dd541c665fb292d664f77604ba694726f298"},{"type":"FIX","url":"https://github.com/go-jose/go-jose/commit/add6a284ea0f844fd6628cba637be5451fe4b28a"},{"type":"FIX","url":"https://github.com/go-jose/go-jose/commit/f4c051a0653d78199a053892f7619ebf96339502"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2631"},"credits":[{"name":"zer0yu"},{"name":"chenjj"}]}