Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/openpubkey/opkssh |
![]() ![]() |
History
Thu, 22 May 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openpubkey
Openpubkey openpubkey Openpubkey opkssh |
|
Weaknesses | CWE-347 | |
CPEs | cpe:2.3:a:openpubkey:openpubkey:*:*:*:*:*:*:*:* cpe:2.3:a:openpubkey:opkssh:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Openpubkey
Openpubkey openpubkey Openpubkey opkssh |
|
Metrics |
cvssV3_1
|
Tue, 13 May 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication. | |
Title | Authentication Bypass in OPKSSH | |
Weaknesses | CWE-305 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: cloudflare
Published: 2025-05-13T16:33:35.195Z
Updated: 2025-05-13T20:11:58.123Z
Reserved: 2025-05-13T16:07:17.466Z
Link: CVE-2025-4658

Updated: 2025-05-13T20:11:52.127Z

Status : Analyzed
Published: 2025-05-13T17:16:04.953
Modified: 2025-05-22T18:43:37.800
Link: CVE-2025-4658

No data.