GHSA-3fx4-7f69-5mmgHighCVSS 7.5

Integer Overflow in go-jose

Published
June 23, 2021
Last Modified
July 6, 2026

🔗 CVE IDs covered (1)

📋 Description

go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts on 32-bit architectures.

🎯 Affected products1

  • go/github.com/square/go-jose:< 0.0.0-20160903044734-789a4c4bd4c1

🔗 References (6)