Vulnerability Description
httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not timing-safe. This makes anyone who uses HS256 signature verification vulnerable to a timing attack that allows the attacker to forge a signature. Version 0.0.19 fixes the issue.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/junkurihara/httpsig-rs/commit/fc095b6ce6043bb808f5d9c4379cf69
- https://github.com/junkurihara/httpsig-rs/security/advisories/GHSA-q7pg-9pr4-mrp
FAQ
What is CVE-2025-59058?
CVE-2025-59058 is a vulnerability with a CVSS score of 5.9 (MEDIUM). httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not timing-safe. This makes anyone who uses HS256 signature veri...
How severe is CVE-2025-59058?
CVE-2025-59058 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59058?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.