CVE-2025-52556
Last modified
CVE-2025-52556 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. In particular, chain verification is performed against the TSR's embedded certificates up to the trusted root(s), but fails to verify the TSR's own signature against the timestamping leaf certificates. Consequently, vulnerable versions perform insufficient signature validation to properly consider a TSR verified, as the attacker can introduce any TSR signature so long as the embedded leaf chains up to some root TSA. This issue has been patched in version 1.0.3. There is no workaround for this issue.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-52556?
How severe is CVE-2025-52556?
How do I fix CVE-2025-52556?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52550E3 Site Supervisor Control (firmware version < 2.31F01) firm…7.2
- CVE-2025-52551E2 Facility Management Systems use a proprietary protocol th…9.3
- CVE-2025-52552FastGPT is an AI Agent building platform. Prior to version 4…6.1
- CVE-2025-52553authentik is an open-source identity provider. After authori…9.6
- CVE-2025-52554n8n is a workflow automation platform. Prior to version 1.99…4.3
- CVE-2025-52555Ceph is a distributed object, block, and file storage platfo…6.5
- CVE-2025-52557Mail-0's Zero is an open-source email solution. In version 0…8.6
- CVE-2025-52558changedetection.io is a free open source web page change det…7
- CVE-2025-52559Zulip is an open-source team chat application. From versions…5.4
- CVE-2025-5256SummaryThis advisory addresses an Open Redirection vulnerabi…5.4
- CVE-2025-52560Kanboard is project management software that focuses on the …8.8
- CVE-2025-52561HTMLSanitizer.jl is a Whitelist-based HTML sanitizer. Prior …6.9
Are you affected by CVE-2025-52556?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
