CVE-2025-4658CRITICAL 9.8EPSS p21.0%
CVE-2025-4658CVE-2025-4658
Description
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.29% probability of exploitation · percentile 21.0% · 2026-06-19T12:03:05Z |
| Published | 2025-05-13 |
| Last modified | 2025-05-22 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass by Primary Weaknesscwe-305 | 0% | live |
| Weakness | Improper Verification of Cryptographic Signaturecwe-347 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.