base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.
History

Sat, 03 May 2025 06:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

threat_severity

Important


Thu, 01 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 19:45:00 +0000

Type Values Removed Values Added
Description base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.
Title base-x homograph attack allows Unicode lookalike characters to bypass validation.
Weaknesses CWE-1007
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-30T19:36:57.356Z

Updated: 2025-05-01T18:49:22.814Z

Reserved: 2025-03-03T15:10:34.079Z

Link: CVE-2025-27611

cve-icon Vulnrichment

Updated: 2025-05-01T18:49:17.756Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-30T20:15:21.430

Modified: 2025-05-02T13:53:40.163

Link: CVE-2025-27611

cve-icon Redhat

Severity : Important

Publid Date: 2025-04-30T19:36:57Z

Links: CVE-2025-27611 - Bugzilla