Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-27611

24
FAUCET Score

CVE-2025-27611 is a high-severity vulnerability affecting base-x versions 4.0.0, 5.0.0, and all versions prior to 3.0.11. This flaw, rated 8.7 CVSS, allows attackers to deceive users into sending funds to unintended addresses due to an issue with bitcoin-style leading zero compression. The vulnerability has been patched in versions 3.0.11, 4.0.1, and 5.0.1. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
CryptocoinjsBase-X
< 3.0.11, = 4.0.0, = 5.0.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 10th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (42)

npmpatch availablevia ghsa
Product: base-xFixed in: 5.0.1
npmpatch availablevia ghsa
Product: base-xFixed in: 4.0.1
npmpatch availablevia ghsa
Product: base-xFixed in: 3.0.11
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0.8Fixed in: org.jboss.hal-hal-parent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-activemq-artemis-0:2.33.0-3.redhat_00017.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-apache-commons-beanutils-0:1.11.0-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-apache-cxf-0:4.0.6-2.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-apache-mime4j-0:0.8.12-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-eap-product-conf-parent-0:800.8.0-1.GA_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-elytron-web-0:4.0.3-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-fastinfoset-0:2.1.1-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-hal-console-0:3.6.24-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-hibernate-0:6.2.36-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-httpcomponents-asyncclient-0:4.1.5-4.redhat_00006.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-jboss-remoting-0:5.0.31-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-jbossws-cxf-0:7.3.3-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-narayana-0:6.0.6-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-neethi-0:3.2.1-1.redhat_00002.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-reactivex-rxjava2-0:2.2.21-3.redhat_00002.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-slf4j-0:2.0.17-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-velocity-0:2.3.0-4.redhat_00010.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-wildfly-0:8.0.8-4.GA_redhat_00006.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Fixed in: eap8-wildfly-elytron-0:2.2.11-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-activemq-artemis-0:2.33.0-3.redhat_00017.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-apache-commons-beanutils-0:1.11.0-1.redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-apache-cxf-0:4.0.6-2.redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-apache-mime4j-0:0.8.12-1.redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-eap-product-conf-parent-0:800.8.0-1.GA_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-elytron-web-0:4.0.3-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-fastinfoset-0:2.1.1-1.redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-hal-console-0:3.6.24-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-hibernate-0:6.2.36-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-httpcomponents-asyncclient-0:4.1.5-4.redhat_00006.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-jboss-remoting-0:5.0.31-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-jbossws-cxf-0:7.3.3-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-narayana-0:6.0.6-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-neethi-0:3.2.1-1.redhat_00002.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-reactivex-rxjava2-0:2.2.21-3.redhat_00002.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-slf4j-0:2.0.17-1.redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-velocity-0:2.3.0-4.redhat_00010.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-wildfly-0:8.0.8-4.GA_redhat_00006.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Fixed in: eap8-wildfly-elytron-0:2.2.11-1.Final_redhat_00001.1.el9eap
View patch

Vendor Advisories (2)

redhatCVE-2025-27611Important

base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation.

Apr 30, 2025
npmGHSA-xq7p-g2vc-g82phigh

Homograph attack allows Unicode lookalike characters to bypass validation.

Apr 30, 2025

References

github.com / cryptocoinjs/base-x/pull/86
github.com / cryptocoinjs/base-x/security/advisories/GHSA-xq7p-g2vc-g82p