PT-2025-37315 · Unknown · Httpsig-Rs

Rasendubi

·

Published

2025-09-12

·

Updated

2025-09-12

·

CVE-2025-59058

CVSS v3.1
5.9
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: httpsig-rs versions prior to 0.0.19
Description: httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. The HMAC signature comparison is not timing-safe in versions prior to 0.0.19, potentially allowing an attacker to forge a signature.
Recommendations: Update to version 0.0.19 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-59058
GHSA-Q7PG-9PR4-MRP2

Affected Products

Httpsig-Rs