Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r5j-37q2-cffw

Опубликовано: 10 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

EPSS

Процентиль: 10%
0.00198
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.1
nvd
13 дней назад

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

EPSS

Процентиль: 10%
0.00198
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-347