GHSA-75rw-34q6-72cr · Severity: critical · Ecosystem: rust — Signature forgery in Biscuit
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any access level. The version 2 of the specification mandates a different algorithm than gamma signatures and as such is not affected by this vulnerability. The Biscuit implementations in Rust, Haskell, Go, Java and Javascript all have published versions following the v2 specification. There are no known workarounds for this issue.
Conclusion & alert: CVE-2022-31053 is rated High Exploit Risk (72.6/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.29%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-12 | 0.22% | 0.29% | +0.07% |
| 2 | 2025-11-21 | 0.26% | 0.22% | -0.04% |
| 3 | 2025-11-18 | — | 0.26% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-75rw-34q6-72cr · Severity: critical · Ecosystem: rust — Signature forgery in Biscuit
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| biscuitsec | biscuit-auth | >= 1.0.0, <= 1.1.0 | cpe:2.3:a:biscuitsec:biscuit-auth:*:*:*:*:*:rust:*:* |
| biscuitsec | biscuit-go | < 2.0.0 | cpe:2.3:a:biscuitsec:biscuit-go:*:*:*:*:*:*:*:* |
| biscuitsec | biscuit-haskell | 0.1.1.0 | cpe:2.3:a:biscuitsec:biscuit-haskell:0.1.1.0:*:*:*:*:*:*:* |
| clever-cloud | biscuit-java | < 2.0.0 | cpe:2.3:a:clever-cloud:biscuit-java:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://eprint.iacr.org/2020/1484 | Exploit Technical Description Third Party Advisory |
| https://github.com/biscuit-auth/biscuit/security/advisories/GHSA-75rw-34q6-72cr | Exploit Third Party Advisory |