CVE-2025-5968501.10.2025, 15:15Kazaar 1.25.12 allows a JWT with none in the alg field.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST5.3 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NmitreCNA------CISA-ADPADP5.3 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NAwaiting analysisThis vulnerability is currently awaiting analysis.Base ScoreCVSS 3.xEPSS ScorePercentile: 11%Referenceshttps://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-59685https://www.kazaar.com/