OpenPubkey Vulnerable to Authentication Bypass
Critical severity
GitHub Reviewed
Published
May 13, 2025
in
openpubkey/openpubkey
•
Updated May 13, 2025
Description
Published by the National Vulnerability Database
May 13, 2025
Published to the GitHub Advisory Database
May 13, 2025
Reviewed
May 13, 2025
Last updated
May 13, 2025
Impact
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.
Patches
Upgrade to v0.10.0 or greater. This vulnerability is not present in versions of OpenPubkey after v0.9.0.
References
CVE-2025-3757
References