CVE-2025-30204 | golang-jwt up to 4.5.1/5.2.1 Authorization Header parse.parseUnverified amplification (GHSA-mh63-6h87-95cp)
A vulnerability classified as problematic has been found in golang-jwt jwt up to 4.5.1/5.2.1. Affected is the function parse.parseUnverified of the component Authorization Header Handler. The manipulation leads to asymmetric resource consumption.
This vulnerability is traded as CVE-2025-30204. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.