CVE-2025-21617: Guzzle OAuth-Subscriber
Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1.
Affected products
- Guzzle OAuth-Subscriber: before 0.8.1 (fixed in 0.8.1)
Published 2025-01-06. Last modified 2026-06-17.