VendorsJose4j Projectjose4jany version
Vulnerabilities

Jose4j Project Jose4j any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-31582
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
Published 2023-10-24 · Modified
7.5EPSS 0.006
CVE-2024-29371
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
Published 2025-12-17 · Modified
7.5EPSS 0.003
CVE-2023-51775
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Published 2023-12-25 · Modified
6.5EPSS 0.009