The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35422.json"