CVE-2025-22868
EUVD-2025-534126.02.2025, 08:14
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| go | jws | 𝑥 < 0.27.0 |
𝑥
= Vulnerable software versions
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cosign |
| ||||||||||||||||||||||||||||||||||||
| cosign-bash-completion |
| ||||||||||||||||||||||||||||||||||||
| cosign-zsh-completion |
| ||||||||||||||||||||||||||||||||||||
| google-cloud-sap-agent |
| ||||||||||||||||||||||||||||||||||||
| google-guest-agent |
| ||||||||||||||||||||||||||||||||||||
| google-osconfig-agent |
| ||||||||||||||||||||||||||||||||||||
| rekor |
|
Red Hat Enterprise Linux Releases