Weak Encryption in Ruby JWT Library Impacting Security Frameworks
CVE-2025-45765
9.1CRITICAL
What is CVE-2025-45765?
The ruby-jwt library version 3.0.0.beta1 has been found to exhibit weak encryption practices, which can leave applications utilizing this library vulnerable to security breaches. The vulnerability stems from the lack of enforced key size policies, which could lead to unauthorized access and inadequate data protection. Users are advised to implement stronger encryption mechanisms and stay updated with newer versions of OpenSSL that impose proper key size restrictions.