Intel

AIKIDO-2025-11005

eProsima.Fast-DDS is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data AuthenticityCVE-2025-24807 Published Dec 30, 2025

45

Medium Risk

This Affects:

c++eProsima.Fast-DDS
0.0.1 - 2.6.9
Fixed in 2.6.10
2.7.0 - 2.10.6
Fixed in 2.10.7
2.11.0 - 2.14.4
Fixed in 2.14.5
3.0.0 - 3.0.1
Fixed in 3.0.2
3.1.0 - 3.1.1
Fixed in 3.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of the package verify expired JWT tokens, allowing unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

eProsima.Fast-DDS is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 2.6.9, 2.7.0 - 2.10.6, 2.11.0 - 2.14.4, 3.0.0 - 3.0.1 and 3.1.0 - 3.1.1.

How to fix this

Upgrade the eProsima.Fast-DDS library to the patch version.