GHSA-6pff-fmh2-4mmf
GitHub Security Advisory
Apache CXF Denial of Service vulnerability in JOSE
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
Affected Packages
Maven
org.apache.cxf:cxf-rt-rs-security-jose
Affected versions:
4.0.0
(fixed in 4.0.5)
Maven
org.apache.cxf:cxf-rt-rs-security-jose
Affected versions:
3.6.0
(fixed in 3.6.4)
Maven
org.apache.cxf:cxf-rt-rs-security-jose
Affected versions:
0
(fixed in 3.5.9)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.