CVE-2025-52556 - CVE House
Back to Database
Status published Critical CVE-2025-52556

rfc3161-client has insufficient verification for timestamp response signatures

Vulnerability Description

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. In particular, chain verification is performed against the TSR's embedded certificates up to the trusted root(s), but fails to verify the TSR's own signature against the timestamping leaf certificates. Consequently, vulnerable versions perform insufficient signature validation to properly consider a TSR verified, as the attacker can introduce any TSR signature so long as the embedded leaf chains up to some root TSA. This issue has been patched in version 1.0.3. There is no workaround for this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52556

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

trailofbits

View all reports →

Affected Software

rfc3161-client
Vulnerable Versions:
< 1.0.3

Timeline

Official Publish: June 21st, 2025
Last Modified: June 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)