CVE-2025-4658 CRITICAL

CVE-2025-4658: Authentication Bypass in OPKSSH

Vendor Opkssh
Product OPKSSH
Weakness CWE-305
Published May 13, 2025
Last update May 13, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

What the vulnerability does

01Description

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication.

Key dates

02Disclosure timeline

May 13, 2025 CVE published
May 13, 2025 Record updated