CVE Explorer
CVE-2025-64186
Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `evervault-go` prior to 1.3.2 that may allow incomplete documents to pass validation. This may cause the client to trust an enclave operator that does not meet expected integrity guarantees. The exploitability of this issue is limited in Evervault-hosted environments as an attacker would require the pre-requisite ability to serve requests from specifi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"evervault-go","vendor":"evervault","versions":[{"status":"affected","version":"< 1.3.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5947ea2a3fb0a3a95a4cf00e57f0a44e24b7ae87c9bf43b1cd66f3e1777b775c · sha256:4d9f578f2f7f07ff… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5947ea2a3fb0a3a95a4cf00e57f0a44e24b7ae87c9bf43b1cd66f3e1777b775c · sha256:4d9f578f2f7f07ff… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5947ea2a3fb0a3a95a4cf00e57f0a44e24b7ae87c9bf43b1cd66f3e1777b775c · sha256:4d9f578f2f7f07ff… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/evervault/evervault-go/commit/7c824d289bba11ec0bea46a338023f5b128bbb28","tags":["x_refsource_MISC"],"url":"https://github.com/evervault/evervault-go/commit/7c824d289bba11ec0bea46a338023f5b128bbb28"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5947ea2a3fb0a3a95a4cf00e57f0a44e24b7ae87c9bf43b1cd66f3e1777b775c · sha256:4d9f578f2f7f07ff… · /containers/cna/references/2
{"name":"https://github.com/evervault/evervault-go/pull/48","tags":["x_refsource_MISC"],"url":"https://github.com/evervault/evervault-go/pull/48"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5947ea2a3fb0a3a95a4cf00e57f0a44e24b7ae87c9bf43b1cd66f3e1777b775c · sha256:4d9f578f2f7f07ff… · /containers/cna/references/1
{"name":"https://github.com/evervault/evervault-go/security/advisories/GHSA-88h9-77c7-p6w4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/evervault/evervault-go/security/advisories/GHSA-88h9-77c7-p6w4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5947ea2a3fb0a3a95a4cf00e57f0a44e24b7ae87c9bf43b1cd66f3e1777b775c · sha256:4d9f578f2f7f07ff… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/evervault/evervault-go/security/advisories/GHSA-88h9-77c7-p6w4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5947ea2a3fb0a3a95a4cf00e57f0a44e24b7ae87c9bf43b1cd66f3e1777b775c · sha256:4d9f578f2f7f07ff… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.