CRITICAL
Authentication Bypass in OPKSSH
Published May 13, 2025
9.3
CRITICALCVSS 4.0
EPSS 0.34%
Description
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication.
Affected products
-
- Version 0.1.0StatusaffectedConstraints<=0.4.0
- Version
OR
- < 0.10.0
- < 0.5.0
No data.
No Red Hat product state for this CVE.
github.com/openpubkey/opkssh
Go
Introduced 0 Fixed 0.5.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/openpubkey/opkssh | 0 | 0.5.0 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-14477 Advisory
- https://github.com/advisories/GHSA-56wx-66px-9j66 Advisory
- https://github.com/openpubkey/opkssh Product
- https://github.com/openpubkey/opkssh/security/advisories/GHSA-56wx-66px-9j66
- https://nvd.nist.gov/vuln/detail/CVE-2025-4658
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cloudflare
Published May 13, 2025
Updated May 13, 2025
Reserved May 13, 2025
Link CVE-2025-4658
CISA Vulnrichment
Updated May 13, 2025
ENISA EUVD
EUVD-2025-14477 GHSA-56WX-66PX-9J66 Assigner cloudflare
Published May 13, 2025
Updated May 13, 2025
Exploited since n/a
Link EUVD-2025-14477