Dvsekhvalnov maintains jose2go, a focused cryptographic library for JSON Web Encryption and related token operations, which despite a narrow product scope sits in application authentication and data-protection workflows across diverse deployments. The observed vulnerabilities cluster around resource-management weaknesses—uncontrolled resource consumption and resource allocation without limits—reflecting the computational demands and parsing complexity inherent to cryptographic operations and token validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dvsekhvalnov over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63811HIGH An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an excepti | Nov 12, 2025 | 7.5 | 24 | NO | NO |
CVE-2023-50658HIGH The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | Feb 29, 2024 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dvsekhvalnov.
Media articles that mention a CVE ID that affects a product developed by Dvsekhvalnov — matched by CVE ID, not by vendor name.