Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23872 | jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who believes that CVE IDs can be assigned for key lengths in specific applications that use a library, and should not be assigned to the default key lengths in a library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record. |
Thu, 07 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jsrsasign: jsrsasign Weak Encryption Vulnerability | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 07 Aug 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 07 Aug 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-326 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 07 Aug 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | jsrsasign v11.1.0 was discovered to contain weak encryption. | jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who believes that CVE IDs can be assigned for key lengths in specific applications that use a library, and should not be assigned to the default key lengths in a library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record. |
| References |
|
Wed, 06 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-327 | |
| Metrics |
cvssV3_1
|
Wed, 06 Aug 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | jsrsasign v11.1.0 was discovered to contain weak encryption. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-26T18:51:17.741Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-45764
Updated: 2025-08-06T19:40:55.517Z
Status : Deferred
Published: 2025-08-06T20:15:28.643
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-45764
OpenCVE Enrichment
No data.
EUVD