bitbucket.org
https://bitbucket.org/b_c/jose4j/commits/19a90a64c47bb07c4aa5462f1316d5c293d81fcf CVE-2024-29371
HIGH
jose4j is vulnerable to DoS via compressed JWE content
Record summary
CVE-2024-29371 has a selected CVSS score of 7.5 (high).
Description
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 17, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.bitbucket.b_c:jose4jBrowse Maven / org.bitbucket.b_c:jose4j | GitHub Advisory | Before 0.9.6 · Fixed in 0.9.6 | affected |
References
4bitbucket.org
https://bitbucket.org/b_c/jose4j/issues/220/vuln-zip-bomb-attack bitbucket.org
https://bitbucket.org/b_c/jose4j/wiki/Home nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-29371