CVE-2025-0509

MEDIUM6.8EPSS 0.07%

Signing Checks Bypass

發布日:2026/5/6修改日:2026/5/8

描述

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.8CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

參考連結(4)