php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
History

Sun, 17 Aug 2025 04:15:00 +0000

Type Values Removed Values Added
Description php-jwt v6.11.0 was discovered to contain weak encryption. php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.

Fri, 15 Aug 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google firebase Php-jwt
CPEs cpe:2.3:a:google:firebase_php-jwt:*:*:*:*:*:*:*:*
Vendors & Products Google
Google firebase Php-jwt

Thu, 31 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-326
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 20:00:00 +0000

Type Values Removed Values Added
Description php-jwt v6.11.0 was discovered to contain weak encryption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-07-31T00:00:00.000Z

Updated: 2025-08-17T03:59:12.347Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-45769

cve-icon Vulnrichment

Updated: 2025-07-31T20:10:23.967Z

cve-icon NVD

Status : Modified

Published: 2025-07-31T20:15:33.150

Modified: 2025-08-17T04:15:39.083

Link: CVE-2025-45769

cve-icon Redhat

No data.