DEBIAN-CVE-2025-30204

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2025-30204
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-30204.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-30204
Upstream
Published
2025-03-21T22:15:26Z
Modified
2025-09-19T06:03:00Z
Summary
[none]
Details

golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.

References

Affected packages

Debian:13

golang-github-golang-jwt-jwt

Package

Name
golang-github-golang-jwt-jwt
Purl
pkg:deb/debian/golang-github-golang-jwt-jwt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0+really4.5.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

golang-github-golang-jwt-jwt-v5

Package

Name
golang-github-golang-jwt-jwt-v5
Purl
pkg:deb/debian/golang-github-golang-jwt-jwt-v5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14

golang-github-golang-jwt-jwt

Package

Name
golang-github-golang-jwt-jwt
Purl
pkg:deb/debian/golang-github-golang-jwt-jwt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0+really4.5.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

golang-github-golang-jwt-jwt-v5

Package

Name
golang-github-golang-jwt-jwt-v5
Purl
pkg:deb/debian/golang-github-golang-jwt-jwt-v5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}