Weak Encryption in Ruby JWT Library Impacting Security Frameworks
CVE-2025-45765

9.1CRITICAL

Key Information:

Vendor

JWT LLC

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-45765?

The ruby-jwt library version 3.0.0.beta1 has been found to exhibit weak encryption practices, which can leave applications utilizing this library vulnerable to security breaches. The vulnerability stems from the lack of enforced key size policies, which could lead to unauthorized access and inadequate data protection. Users are advised to implement stronger encryption mechanisms and stay updated with newer versions of OpenSSL that impose proper key size restrictions.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.