Go-jose Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-34986

    Go JOSE affect by a panic in JWE decryption

    Last Modified: Sep 10, 2026
    Published: Apr 06, 2026

    CVE-2024-28180

    Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

    Last Modified: Dec 03, 2025
    Published: Mar 09, 2024

    CVE-2016-9121

    go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.

    Last Modified: Apr 20, 2025
    Published: Mar 28, 2017

    CVE-2016-9122

    go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

    Last Modified: Apr 20, 2025
    Published: Mar 28, 2017

    CVE-2016-9123

    go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts on 32-bit architectures.

    Last Modified: Apr 20, 2025
    Published: Mar 28, 2017
    Items Per Page
    Go-Jose_Project Vulnerabilities & Security CVEs | CVE-DB