{"id":"CVE-2025-3757","aliases":["GHSA-537f-gxgm-3jjq","GO-2025-3679"],"url":"https://o3.security/vulnerability/CVE-2025-3757","summary":"Authentication Bypass in OpenPubKey","details":"### Impact\n\nVersions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.\n\n### Patches\n\nUpgrade to v0.10.0 or greater. This vulnerability is not present in versions of OpenPubkey after v0.9.0. \n\n### References\n\n[CVE-2025-3757 ](https://www.cve.org/CVERecord?id=CVE-2025-3757)","published":"2025-05-13T16:33:18.074Z","modified":"2026-08-12T03:51:35.410003965Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openpubkey/openpubkey","fixedVersion":"0.10.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3757.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3757"},{"type":"PACKAGE","url":"https://github.com/openpubkey/openpubkey"},{"type":"WEB","url":"https://github.com/openpubkey/openpubkey/security/advisories/GHSA-537f-gxgm-3jjq"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.410003965Z"}}