CVE-2025-45767
Severity CVSS v4.0:
Pending analysis
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
01/08/2025
Last modified:
21/08/2025
Description
jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.
Impact
Base Score 3.x
7.00
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://gist.github.com/ZupeiNie/705a606fbb99f3bb8c9b51e5bc13c91d
- https://gist.github.com/ZupeiNie/705a606fbb99f3bb8c9b51e5bc13c91d?permalink_comment_id=5711572#gistcomment-5711572
- https://github.com/panva
- https://github.com/panva/jose
- https://github.com/panva/jose/blob/1e36dd29e76511e06737e5d5d500d81e01a9c3d2/src/lib/check_key_length.ts#L6-L7
- https://github.com/panva/jose/discussions/813



