Threats Tagged 'ghsa-3prj-6hqw-cm82'
View all threats tagged with 'ghsa-3prj-6hqw-cm82'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-3prj-6hqw-cm82'
Click on any threat for detailed analysis and mitigation recommendations
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service 0 The PHP JWT Library contains a vulnerability in its PBES2-HS*+A*KW key unwrapping implementation where the iteration count parameter (p2c) from the attacker-controlled JOSE header is not properly bounded. This allows an unauthenticated attacker to specify an extremely large iteration count, causing excessive CPU consumption during PBKDF2 computation and resulting in a denial of service. The vulnerability affects applications that enable PBES2 algorithms for decryption. A patch has been introduced that enforces a configurable maximum iteration count to prevent CPU amplification attacks. Join the discussion | GCVE Database | 06/18/2026, 21:09:01 UTC Added: 07/16/2026, 10:36:06 UTC |
Showing 1 to 1 of 1 result