Количество 2
Количество 2

CVE-2025-21617
Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1.
GHSA-237r-r8m4-4q88
Guzzle OAuth Subscriber has insufficient nonce entropy
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2025-21617 Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1. | 0% Низкий | 7 месяцев назад | |
GHSA-237r-r8m4-4q88 Guzzle OAuth Subscriber has insufficient nonce entropy | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу