Go-jose-project
3 CVEs tracked since 2017. Since Mar 2017, none of them reached CISA KEV.
Go-jose-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-03 | 3 | 0 |
Products
The products that kept showing up in Go-jose-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Go-jose-project.
- CVE-2026-34986Go JOSE affect by a panic in JWE decryption7.5
- CVE-2024-28180Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)4.3
- CVE-2016-9123go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts on 32-bit architect...7.5
- CVE-2016-9122go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicat...7.5
- CVE-2016-9121go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received ...9.1
The record
- Peak rank
- #109 in Mar 2017
- Busiest month shown
- Mar 2017, 3 CVEs
- Months with a KEV entry
- 0 since Mar 2017
- Monthly snapshots
- 1 since 2017