AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-28176

MEDIUM · CVSS 4.9 EPSS 2.08% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-03-09 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.9. It affects Java. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-28176
Severity
MEDIUM
CVSS
4.9
EPSS
2.08%
Java

Original NVD Description

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

Related CVEs

Other vulnerabilities affecting the same vendor(s)