FlawAtlas
Search the atlas
CVE-2025-3757 Critical

OpenPubkey Vulnerable to Authentication Bypass in github.com/openpubkey/openpubkey

OpenPubkey Vulnerable to Authentication Bypass in github.com/openpubkey/openpubkey

Exploit probability 0.4%
Published May 15, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

15 explicit affected versions

Go github.com/openpubkey/openpubkey
Go github.com/openpubkey/openpubkey

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-3757

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

View original source
Open Source Vulnerabilities GO-2025-3679

OpenPubkey Vulnerable to Authentication Bypass in github.com/openpubkey/openpubkey

View original source
Open Source Vulnerabilities GHSA-537f-gxgm-3jjq

### Impact Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. ### Patches Upgrade to v0.10.0 or greater. This vulnerability is not present in versions of OpenPubkey after v0.9.0. ### References [CVE-2025-3757 ](https://www.cve.org/CVERecord?id=CVE-2025-3757)

View original source

05 / REFERENCES

Further evidence