CVE-2025-22868
HIGHDescription
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| go | jws |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-22868? +
How severe is CVE-2025-22868? +
What products are affected by CVE-2025-22868? +
How do I check if I'm vulnerable to CVE-2025-22868? +
Related Vulnerabilities
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user …
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A …
A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported …
Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside …
An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker …
The initial code parsing the manifest did not check the content of the file names yet later code assumed that …