Intel

AIKIDO-2025-10963

firebase/php-jwt is vulnerable to Inadequate Encryption Strength

Inadequate Encryption StrengthCVE-2025-45769 Published Dec 16, 2025

43

Medium Risk

This Affects:

PHPfirebase/php-jwt
0.1.0 - 6.11.1
Fixed in 7.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Inadequate Encryption Strength due to insufficient HMAC and RSA key lengths validation, which do not meet recommended security standards.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

firebase/php-jwt is vulnerable to Inadequate Encryption Strength in versions 0.1.0 - 6.11.1.

How to fix this

Upgrade the firebase/php-jwt library to the patch version.