CVE-2025-21617: Guzzle OAuth-Subscriber

Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1.

Affected products

  • Guzzle OAuth-Subscriber: before 0.8.1 (fixed in 0.8.1)

Published 2025-01-06. Last modified 2026-06-17.