1
+ {
2
+ "schema_version" : " 1.3.1" ,
3
+ "id" : " GO-2025-3485" ,
4
+ "modified" : " 0001-01-01T00:00:00Z" ,
5
+ "published" : " 0001-01-01T00:00:00Z" ,
6
+ "aliases" : [
7
+ " CVE-2025-27144" ,
8
+ " GHSA-c6gw-w398-hv78"
9
+ ],
10
+ "summary" : " DoS in go-jose Parsing in github.com/go-jose/go-jose" ,
11
+ "details" : " DoS in go-jose Parsing in github.com/go-jose/go-jose" ,
12
+ "affected" : [
13
+ {
14
+ "package" : {
15
+ "name" : " github.com/go-jose/go-jose" ,
16
+ "ecosystem" : " Go"
17
+ },
18
+ "ranges" : [
19
+ {
20
+ "type" : " SEMVER" ,
21
+ "events" : [
22
+ {
23
+ "introduced" : " 0"
24
+ }
25
+ ]
26
+ }
27
+ ],
28
+ "ecosystem_specific" : {}
29
+ },
30
+ {
31
+ "package" : {
32
+ "name" : " github.com/go-jose/go-jose/v3" ,
33
+ "ecosystem" : " Go"
34
+ },
35
+ "ranges" : [
36
+ {
37
+ "type" : " SEMVER" ,
38
+ "events" : [
39
+ {
40
+ "introduced" : " 0"
41
+ },
42
+ {
43
+ "fixed" : " 3.0.4"
44
+ }
45
+ ]
46
+ }
47
+ ],
48
+ "ecosystem_specific" : {
49
+ "imports" : [
50
+ {
51
+ "path" : " github.com/go-jose/go-jose/v3" ,
52
+ "symbols" : [
53
+ " ParseDetached" ,
54
+ " ParseEncrypted" ,
55
+ " ParseSigned" ,
56
+ " rawJSONWebEncryption.sanitized" ,
57
+ " rawJSONWebSignature.sanitized"
58
+ ]
59
+ }
60
+ ]
61
+ }
62
+ },
63
+ {
64
+ "package" : {
65
+ "name" : " github.com/go-jose/go-jose/v4" ,
66
+ "ecosystem" : " Go"
67
+ },
68
+ "ranges" : [
69
+ {
70
+ "type" : " SEMVER" ,
71
+ "events" : [
72
+ {
73
+ "introduced" : " 0"
74
+ },
75
+ {
76
+ "fixed" : " 4.0.5"
77
+ }
78
+ ]
79
+ }
80
+ ],
81
+ "ecosystem_specific" : {
82
+ "imports" : [
83
+ {
84
+ "path" : " github.com/go-jose/go-jose/v4" ,
85
+ "symbols" : [
86
+ " ParseEncrypted" ,
87
+ " ParseEncryptedCompact" ,
88
+ " ParseSignedCompact"
89
+ ]
90
+ }
91
+ ]
92
+ }
93
+ },
94
+ {
95
+ "package" : {
96
+ "name" : " github.com/square/go-jose" ,
97
+ "ecosystem" : " Go"
98
+ },
99
+ "ranges" : [
100
+ {
101
+ "type" : " SEMVER" ,
102
+ "events" : [
103
+ {
104
+ "introduced" : " 0"
105
+ }
106
+ ]
107
+ }
108
+ ],
109
+ "ecosystem_specific" : {}
110
+ }
111
+ ],
112
+ "references" : [
113
+ {
114
+ "type" : " ADVISORY" ,
115
+ "url" : " https://github.com/go-jose/go-jose/security/advisories/GHSA-c6gw-w398-hv78"
116
+ },
117
+ {
118
+ "type" : " FIX" ,
119
+ "url" : " https://github.com/go-jose/go-jose/commit/99b346cec4e86d102284642c5dcbe9bb0cacfc22"
120
+ },
121
+ {
122
+ "type" : " WEB" ,
123
+ "url" : " https://github.com/go-jose/go-jose/releases/tag/v4.0.5"
124
+ },
125
+ {
126
+ "type" : " WEB" ,
127
+ "url" : " https://go.dev/issue/71490"
128
+ },
129
+ {
130
+ "type" : " WEB" ,
131
+ "url" : " https://go.dev/issue/71490"
132
+ }
133
+ ],
134
+ "database_specific" : {
135
+ "url" : " https://pkg.go.dev/vuln/GO-2025-3485" ,
136
+ "review_status" : " REVIEWED"
137
+ }
138
+ }
0 commit comments