VYPR

OAuth Subscriber

by Guzzle

Source repositories

CVEs (1)

  • CVE-2025-21617MedJan 6, 2025
    risk 0.34cvss epss 0.00

    Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is…