Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/openpubkey/opkssh |
![]() ![]() |
History
Tue, 13 May 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication. | |
Title | Authentication Bypass in OPKSSH | |
Weaknesses | CWE-305 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: cloudflare
Published: 2025-05-13T16:33:35.195Z
Updated: 2025-05-13T20:11:58.123Z
Reserved: 2025-05-13T16:07:17.466Z
Link: CVE-2025-4658

Updated: 2025-05-13T20:11:52.127Z

Status : Awaiting Analysis
Published: 2025-05-13T17:16:04.953
Modified: 2025-05-13T19:35:18.080
Link: CVE-2025-4658

No data.