GO-2023-2379

    Dashboard / Vulnerabilities / GO-2023-2379

    GO-2023-2379

    Published: 11 Dec 2023Last Modified: 4 Feb 2026

    Summary: Denial of service due to malicious parameters in github.com/lestrrat-go/jwx

    Details: The JWE key management algorithms based on PBKDF2 require a JOSE Header Parameter called p2c (PBES2 Count). This parameter dictates the number of PBKDF2 iterations needed to derive a CEK wrapping key. Its purpose is to intentionally slow down the key derivation function, making password brute-force and dictionary attacks more resource-intensive. However, if an attacker sets the p2c parameter in JWE to a very large number, it can cause excessive computational consumption.

    Affected packages

    Package

    Name: github.com/lestrrat-go/jwx

    Purl: pkg:golang/github.com/lestrrat-go/jwx

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.2.27

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2023-2379 | CVE-DB