Openpubkey is a focused cryptographic authentication framework with a narrow product scope centered on the core openpubkey library and its SSH integration (opkssh), designed to provide public-key-based credential verification. The vulnerability exposures observed in this vendor cluster around authentication and signature-verification mechanics, specifically authentication bypass through primary weaknesses and improper cryptographic signature validation, which are structurally critical to the framework's security model. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpubkey over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3757CRITICAL Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. | May 13, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4658CRITICAL Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPu | May 13, 2025 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpubkey.
Media articles that mention a CVE ID that affects a product developed by Openpubkey — matched by CVE ID, not by vendor name.