Evervault is a focused encryption and data-security platform provider whose disclosed vulnerabilities center on its core product and reflect weaknesses in cryptographic signature verification. The observed pattern of improper cryptographic verification highlights the critical nature of authentication and integrity validation in security-oriented middleware, and defenders relying on this vendor should prioritize understanding the scope and remediation of reported signature-validation flaws. Current vulnerability counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evervault over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64186MEDIUM Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `evervault-go` prior to 1.3.2 tha | Nov 12, 2025 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evervault.
Media articles that mention a CVE ID that affects a product developed by Evervault — matched by CVE ID, not by vendor name.