NONE · 0

CVE-2025-21617

Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave serve...

Vulnerability Description

Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-21617?

CVE-2025-21617 is a documented vulnerability. Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave serve...

How severe is CVE-2025-21617?

CVSS scoring is not yet available for CVE-2025-21617. Check NVD for updates.

Is there a patch for CVE-2025-21617?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.