CVE-2025-63811 — Uncontrolled Resource Consumption in Dvsekhvalnov Jose2go
Severity
7.5HIGHNVD
EPSS
0.1%
top 84.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateNov 18
Description
An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
4OSV▶
Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token high compression ratio in github.com/dvsekhvalnov/jose2go↗2025-11-18
📋Vendor Advisories
1Debian▶
CVE-2025-63811: golang-github-dvsekhvalnov-jose2go - An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an att...↗2025