Skip to content

[GHSA-2x45-7fc3-mxwq] php-jwt contains weak encryption#6954

Merged
advisory-database[bot] merged 1 commit intoderhansen/advisory-improvement-6954from
derhansen-GHSA-2x45-7fc3-mxwq
Feb 27, 2026
Merged

[GHSA-2x45-7fc3-mxwq] php-jwt contains weak encryption#6954
advisory-database[bot] merged 1 commit intoderhansen/advisory-improvement-6954from
derhansen-GHSA-2x45-7fc3-mxwq

Conversation

@derhansen
Copy link

Updates

  • Affected products

Comments
The CVE has been disputed https://nvd.nist.gov/vuln/detail/CVE-2025-45769 and the advisory should be removed from the database.

@ohader
Copy link

ohader commented Feb 18, 2026

I summarized the aspects after evaluating and applying the CNA rules (as stated for the disputed state in the underlying CVE): firebase/php-jwt#620 (comment)

From my (personal) point of view, CVE-2025-45769 should be REJECTED.
(I'm aware that the CVE was submitted to a different CNA)

@shelbyc
Copy link
Contributor

shelbyc commented Feb 18, 2026

I posted a comment about the review of GHSA-2x45-7fc3-mxwq to firebase/php-jwt#620 (comment).

@shelbyc
Copy link
Contributor

shelbyc commented Feb 27, 2026

Since the discussion in firebase/php-jwt#620 has ended, I'm closing this PR because, rather than withdrawing the advisory, my teammates and I decided to keep GHSA-2x45-7fc3-mxwq and lower the CVSS. The changes to GHSA-2x45-7fc3-mxwq, including a link to firebase/php-jwt#620 in the references, should appear shortly.

@shelbyc shelbyc closed this Feb 27, 2026
@advisory-database advisory-database bot merged commit 85b51b7 into derhansen/advisory-improvement-6954 Feb 27, 2026
4 of 5 checks passed
@advisory-database
Copy link
Contributor

Hi @derhansen! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the derhansen-GHSA-2x45-7fc3-mxwq branch February 27, 2026 18:57
@shelbyc
Copy link
Contributor

shelbyc commented Feb 27, 2026

I merged the credit addition instead of closing the credit addition. 😳 @derhansen Are you OK with your name appearing as an Analyst on the side of GHSA-2x45-7fc3-mxwq or would you prefer to have your name removed?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants