PT-2025-18780 · Jose4J+2 · Jose4J+2
Published
2024-03-05
·
Updated
2026-05-18
·
CVE-2024-29371
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
jose4j versions prior to 0.9.5
Description
An attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. Processing this token by the server results in significant memory allocation and processing time during decompression.
Recommendations
Update to version 0.9.5 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Confluence
Red Os
Jose4J