An attacker controlled input of a PBES2 encrypted JWE blob can have a very large p2c value that, when decrypted, produces a denial-of-service.
{
"nvd_published_at": null,
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed_at": "2023-12-20T20:31:57Z",
"github_reviewed": true
}