Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14478 | OpenPubkey Vulnerable to Authentication Bypass |
Github GHSA |
GHSA-537f-gxgm-3jjq | OpenPubkey Vulnerable to Authentication Bypass |
| Link | Providers |
|---|---|
| https://github.com/openpubkey/openpubkey |
|
Fri, 23 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openpubkey
Openpubkey openpubkey |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:openpubkey:openpubkey:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpubkey
Openpubkey openpubkey |
|
| Metrics |
cvssV3_1
|
Tue, 13 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. | |
| Title | Authentication Bypass in OpenPubKey | |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2025-05-13T20:12:58.087Z
Reserved: 2025-04-17T11:00:58.093Z
Link: CVE-2025-3757
Updated: 2025-05-13T20:12:51.062Z
Status : Analyzed
Published: 2025-05-13T17:16:04.253
Modified: 2025-05-23T18:56:34.540
Link: CVE-2025-3757
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA