CVE-2025-22865

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 28, 2025

Summary

CVE-2025-22865 is a vulnerability in the handling of RSA keys. If a key is missing its Certificate Revocation List (CRL) or Certificate Transparency (CT) values, the ParsePKCS1PrivateKey function will panic when attempting to verify the key's well-formedness. This issue could potentially allow an attacker to bypass security checks or cause a denial of service. It is recommended to update affected systems to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share