CVE-2025-2885
MEDIUMDescription
Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
Is your site exposed to CVE-2025-2885?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| amazon | tough |
References
Frequently Asked Questions
What is CVE-2025-2885? +
How severe is CVE-2025-2885? +
What products are affected by CVE-2025-2885? +
How do I check if I'm vulnerable to CVE-2025-2885? +
Related Vulnerabilities
Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the …
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and …
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 …