StackRadar

CVE-2023-49290

Medium

Advisory

Published 5 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
55
deployed by those charts
Fix available
2 of 2
affected packages

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 55 images.

Affected packageAffected versionsFixed inImages
github.com/lestrrat-go/jwxgolangv0.9.0, v1.0.2, v1.1.5, v1.1.7+11 more1.2.2750
github.com/lestrrat-go/jwx/v2golangv2.0.8, v2.0.11, v2.0.162.0.185
OSV records
GHSA-7f9x-gw85-8grf
Also known as
GO-2023-2379

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2023-49290.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
github.com/lestrrat-go/jwx@v1.2.1
1.2.27

Open the chart page →

2,081
traefik-jwt-decodetraefik-jwt-decode0.1.01 of 1See more

traefik-jwt-decode traefik-jwt-decode 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49290.

Container imageDigestPackageFixed in
simonschneider/traefik-jwt-decode:latestd674ac370f80
github.com/lestrrat-go/jwx@v1.2.6
1.2.27

Open the chart page →

1,310
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-49290.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
github.com/lestrrat-go/jwx@v1.2.25
1.2.27

Open the chart page →

4,960
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-49290.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/lestrrat-go/jwx@v1.2.25
1.2.27

Open the chart page →

6,232
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2023-49290.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
github.com/lestrrat-go/jwx@v1.0.2
1.2.27

Open the chart page →

4,086
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-49290.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
github.com/lestrrat-go/jwx@v1.2.7
1.2.27

Open the chart page →

6,138

Container images carrying it

55 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
github.com/lestrrat-go/jwx@v1.2.19
1.2.27
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
github.com/lestrrat-go/jwx@v1.2.25
1.2.27
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
github.com/lestrrat-go/jwx@v1.2.25
1.2.27
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
github.com/lestrrat-go/jwx@v1.2.17
1.2.27
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
github.com/lestrrat-go/jwx@v1.2.25
1.2.27
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.