PT-2025-20928 · Unknown+1 · Openpubkey+1

Ethan Heilman

·

Published

2025-05-13

·

Updated

2025-05-20

·

CVE-2025-4658

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OpenPubkey library versions prior to 0.10.0 OPKSSH versions prior to 0.5.0
Description: The issue allows a specially crafted JWS to bypass signature verification. This affects OPKSSH as it depends on the OpenPubkey library for authentication, enabling an attacker to bypass OPKSSH authentication.
Recommendations: For OpenPubkey library versions prior to 0.10.0, update to version 0.10.0 or later to resolve the issue. For OPKSSH versions prior to 0.5.0, update to version 0.5.0 or later to resolve the issue.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-4658
GHSA-56WX-66PX-9J66
GO-2025-3680
OPENSUSE-SU-2025:15135-1

Affected Products

Opkssh
Openpubkey