Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Aug 6, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/dvsekhvalnov/jose2go v1.5.0 -> v1.7.0 age adoption passing confidence

GitHub Vulnerability Alerts

GHSA-mhpq-9638-x6pw

An attacker controlled input of a PBES2 encrypted JWE blob can have a very large p2c value that, when decrypted, produces a denial-of-service.

CVE-2023-50658

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVE-2025-63811

An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.


Release Notes

dvsekhvalnov/jose2go (github.com/dvsekhvalnov/jose2go)

v1.7.0

Compare Source

v1.6.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title fix(deps): update module github.com/dvsekhvalnov/jose2go to v1.6.0 [security] fix(deps): update module github.com/dvsekhvalnov/jose2go to v1.7.0 [security] Nov 15, 2025
@renovate renovate bot force-pushed the renovate/go-github.colasdn.workers.dev-dvsekhvalnov-jose2go-vulnerability branch from 18af2ce to d468363 Compare November 15, 2025 01:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant