==========================
== Gharib Personal Blog ==
==========================
A Techi Personal Blog

CVE-2025-30204 - golang-jwt Denial of Service DoS

CVE-2025-30204 - golang-jwt Denial of Service DoS

CVE ID : CVE-2025-30204 Published : March 21, 2025, 10:15 p.m. | 6 hours, 31 minutes ago Description : golang-jwt is a Go implementation of JSON Web Tokens. Prior to 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result,

CVE ID : CVE-2025-30204
Published : March 21, 2025, 10:15 p.m. | 6 hours, 31 minutes ago
Description : golang-jwt is a Go implementation of JSON Web Tokens. Prior to 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function’s argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Source