CVE-2024-21491

MEDIUM
Published Feb 13, 2024 Modified May 9, 2025 CWE-288 CWE-347

Description

Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches the beginning of the actual signature. **Note:** The attacker would need to know a victim uses the Rust library for verification,no easy way to automatically check that; and uses webhooks by a service that uses Svix, and then figure out a way to craft a malicious payload that will actually include all of the correct identifiers needed to trick the receivers to cause actual issues.

Is your site exposed to CVE-2024-21491?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.9
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N

Weakness Type (CWE)

CWE-288 CWE-288
CWE-347 CWE-347

Affected Products

Vendor Product
svix svix-webhooks

References

Frequently Asked Questions

What is CVE-2024-21491? +
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches the beginning of the actual signature. **Note:** The attacker would need to know a victim uses the Rust library for verification,no easy way to automatically check that; and uses webhooks by a service that uses Svix, and then figure out a way to craft a malicious payload that will actually include all of the correct identifiers needed to trick the receivers to cause actual issues. It has a CVSS v3.1 base score of 5.9 (MEDIUM).
How severe is CVE-2024-21491? +
CVE-2024-21491 has a CVSS v3.1 score of 5.9 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-21491? +
CVE-2024-21491 affects products from svix, specifically: svix-webhooks. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-21491? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-21491 — free, no signup required.