CVE-2025-43866

Severity CVSS v4.0:
LOW
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
12/06/2025
Last modified:
17/09/2025

Description

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent. This vulnerability is fixed in 4.11.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:* 4.11.0 (excluding)