g
go-jose project
Security Risk Profile
43
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 28, 2017 to present
5
Total CVEs
4
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
43/100
medium
Severity Distribution
Critical
1High
3Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Integer Overflow
1
2
Weak Encryption
1
Most Affected Products
1. Go-jose Project Go-jose8
2. redhat/go-jose3
3. go/github.com/go-jose/go-jose/v32
4. go/github.com/go-jose/go-jose/v42
5. Microsoft cbl2 telegraf 1.29.4-152
Recent Vulnerabilities
See more →CVE-2026-34986
CVSS 7.5high
Go JOSE affect by a panic in JWE decryption
Apr 3, 2026
CVE-2024-28180
CVSS 4.3EPSS 0%medium
Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)
Mar 7, 2024
CVE-2016-9123
CVSS 7.5high
Mar 28, 2017
CVE-2016-9121
CVSS 9.1critical
Mar 28, 2017
CVE-2016-9122
CVSS 7.5high
Mar 28, 2017
Monitor go-jose project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.