CVE-2025-3757

9.8CRITICAL

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

Published: 5/13/2025Updated: 5/23/2025

Description

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

AI AnalysisPowered by AI

Affected Products

openpubkeyopenpubkey

References