erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.
Stay updated with the latest patches and releases. Plan your sofware desisgn. Avoid common known vulnerabilities fixed by the open source community
Latest patch release: 1.7.9
Latest minor release: 1.11.12
Latest major release: --
Maintain your licence declarations and avoid unwanted licences to protect your IP the way you intended.
MIT - MIT License