From b63934763085eba30af8565b5b03d34393c882a7 Mon Sep 17 00:00:00 2001 From: Pieter Hoste Date: Tue, 23 Jun 2026 13:04:51 +0200 Subject: [PATCH] Improve GHSA-3prj-6hqw-cm82 --- .../GHSA-3prj-6hqw-cm82.json | 47 +++++++++++++++++-- 1 file changed, 44 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2026/06/GHSA-3prj-6hqw-cm82/GHSA-3prj-6hqw-cm82.json b/advisories/github-reviewed/2026/06/GHSA-3prj-6hqw-cm82/GHSA-3prj-6hqw-cm82.json index 81893c3ee3a6d..4ebdd340fca49 100644 --- a/advisories/github-reviewed/2026/06/GHSA-3prj-6hqw-cm82/GHSA-3prj-6hqw-cm82.json +++ b/advisories/github-reviewed/2026/06/GHSA-3prj-6hqw-cm82/GHSA-3prj-6hqw-cm82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3prj-6hqw-cm82", - "modified": "2026-06-18T21:09:01Z", + "modified": "2026-06-18T21:09:05Z", "published": "2026-06-18T21:09:01Z", "aliases": [], "summary": "PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service", @@ -42,10 +42,10 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "4.1.0" }, { - "last_affected": "4.1.6" + "fixed": "4.1.7" } ] } @@ -88,6 +88,47 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "web-token/jwt-framework" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.4.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "web-token/jwt-framework" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, + { + "fixed": "4.1.7" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 4.0.7" + } } ], "references": [