GHSA-hhhv-q57g-882q · Severity: medium · Ecosystem: npm — jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext
jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.
Conclusion & alert: CVE-2024-28176 is rated Moderate Risk (43.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.57%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-28 | 0.42% | 0.57% | +0.15% |
| 2 | 2025-12-06 | 0.18% | 0.42% | +0.24% |
| 3 | 2025-11-21 | — | 0.18% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.9 | 3.1 | MEDIUM |
|
1.2 | 3.6 | [email protected] |
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
GHSA-hhhv-q57g-882q · Severity: medium · Ecosystem: npm — jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2024-28176 |
ubuntu
|
medium | CVE-2024-28176 medium priority: Ubuntu including 1 source packages (node-jose), 8 status rows across 8 suites (focal, jammy, mantic, noble, oracular, plucky, questing, upstream): needs-triage 4, ignored 3, DNE 1. | https://ubuntu.com/security/CVE-2024-28176 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| jose_project | jose | < 2.0.7 | cpe:2.3:a:jose_project:jose:*:*:*:*:*:node.js:*:* |
| jose_project | jose | >= 3.0.0, < 4.15.5 | cpe:2.3:a:jose_project:jose:*:*:*:*:*:node.js:*:* |
| fedoraproject | fedora | >= 38, <= 40 | cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/panva/jose/commit/02a65794f7873cdaf12e81e80ad076fcdc4a9314 | Patch |
| https://github.com/panva/jose/commit/1b91d88d2f8233f3477a5f4579aa5f8057b2ee8b | Patch |
| https://github.com/panva/jose/security/advisories/GHSA-hhhv-q57g-882q | Vendor Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/I6MMWFBOXJA6ZCXNVPDFJ4XMK5PVG5RG/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/KXKGNCRU7OTM5AHC7YIYBNOWI742PRMY/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/UG5FSEYJ3GP27FZXC5YAAMMEC5XWKJHG/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/UJO2U5ACZVACNQXJ5EBRFLFW6DP5BROY/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/XJDO5VSIAOGT2WP63AXAAWNRSVJCNCRH/ | Mailing List Third Party Advisory |