{"id":"CVE-2025-3757","aliases":["GHSA-537f-gxgm-3jjq","GO-2025-3679"],"url":"https://o3.security/vulnerability/CVE-2025-3757","summary":"Authentication Bypass in OpenPubKey","details":"Versions of OpenPubkey library prior to 0.10.0  contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.","published":"2025-05-13T16:33:18.074Z","modified":"2026-07-15T01:49:17.056786173Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openpubkey/openpubkey","fixedVersion":"0.10.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3757.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3757"},{"type":"PACKAGE","url":"https://github.com/openpubkey/openpubkey"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:17.056786173Z"}}