Vulnerability Description
jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/ZupeiNie/705a606fbb99f3bb8c9b51e5bc13c91d
- https://gist.github.com/ZupeiNie/705a606fbb99f3bb8c9b51e5bc13c91d?permalink_comm
- https://github.com/panva
- https://github.com/panva/jose
- https://github.com/panva/jose/blob/1e36dd29e76511e06737e5d5d500d81e01a9c3d2/src/
- https://github.com/panva/jose/discussions/813
FAQ
What is CVE-2025-45767?
CVE-2025-45767 is a vulnerability with a CVSS score of 7.0 (HIGH). jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final p...
How severe is CVE-2025-45767?
CVE-2025-45767 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45767?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.