OpenPubkey Library Signature Bypass Vulnerability in JWS Verification

Vulnerability

A vulnerability exists in the OpenPubkey library in versions prior to 0.10.0, allowing a specially crafted JSON Web Signature (JWS) to bypass signature verification. This issue arises from the library's handling of JWS signatures, which can be exploited to undermine the integrity of the signature verification process.

Impact

Exploitation of this vulnerability allows for the bypassing of signature verification in JWS, potentially leading to unauthorized actions or the acceptance of fraudulent signatures.

Remediation

Users can upgrade to OpenPubkey version 0.10.0 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.