An attacker controlled input of a PBES2 encrypted JWE blob can have a very large p2c value that, when decrypted, produces a denial-of-service.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-2409" }
{ "imports": [ { "path": "github.com/dvsekhvalnov/jose2go", "symbols": [ "Compress", "Decode", "DecodeBytes", "Encrypt", "EncryptBytes", "Pbse2HmacAesKW.Unwrap", "Pbse2HmacAesKW.WrapNewKey", "decrypt", "encrypt" ] } ] }