Jose4j ProjectCVEs & Vulnerabilities
3 CVEs affecting Jose4j Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
jose4j 3
CVE-2024-29371HIGH
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
17 Dec 2025
7.5
CVSS
CVE-2023-51775MEDIUM
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
29 Feb 2024
6.5
CVSS
CVE-2023-31582HIGH
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
25 Oct 2023
7.5
CVSS
← PrevPage 1 / 1Next →