PT-2025-32312 · Ruby-Jwt+1 · Ruby-Jwt+1

Zupeinie

·

Published

2025-08-07

·

Updated

2025-08-08

·

CVE-2025-45765

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ruby-jwt version 3.0.0.beta1
Description ruby-jwt v3.0.0.beta1 contains weak encryption. The supplier notes that key size is not enforced by the library itself, and restrictions imposed by recent versions of OpenSSL may apply to users of the gem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2025-45765

Affected Products

Debian
Ruby-Jwt