First published: Tue May 13 2025(Updated: )
### Impact Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. ### Patches Upgrade to v0.10.0 or greater. This vulnerability is not present in versions of OpenPubkey after v0.9.0. ### References [CVE-2025-3757 ](https://www.cve.org/CVERecord?id=CVE-2025-3757)
Credit: cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenPubkey | <0.10.0 | |
go/github.com/openpubkey/openpubkey | <0.10.0 | 0.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3757 is classified with a medium severity rating due to its potential to bypass signature verification.
To fix CVE-2025-3757, update the OpenPubkey library to version 0.10.0 or later.
CVE-2025-3757 affects versions of the OpenPubkey library prior to 0.10.0.
CVE-2025-3757 is a signature verification bypass vulnerability that involves specially crafted JSON Web Signatures (JWS).
Developers and organizations using the OpenPubkey library below version 0.10.0 are impacted by CVE-2025-3757.