Lestrrat Go maintains a specialized JWT (JSON Web Token) cryptographic library, the jwx package, which occupies a narrow but foundational role in applications requiring token signing and validation. The limited disclosure history reflects the focused scope of this library rather than broad product coverage; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lestrrat Go over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21664HIGH jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. Calling `jws.Parse` with a JSON serialized payload where the `signature` fi | Jan 9, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-28122MEDIUM JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause a D | Mar 9, 2024 | 6.8 | 18 | NO | NO |
CVE-2023-49290MEDIUM lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p2c parameter set too high in JWE's algorithm PBES2-* could l | Dec 5, 2023 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lestrrat Go.
Media articles that mention a CVE ID that affects a product developed by Lestrrat Go — matched by CVE ID, not by vendor name.