CVE-2025-2888
MEDIUMDescription
During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
Is your site exposed to CVE-2025-2888?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| amazon | tough |
References
Frequently Asked Questions
What is CVE-2025-2888? +
How severe is CVE-2025-2888? +
What products are affected by CVE-2025-2888? +
How do I check if I'm vulnerable to CVE-2025-2888? +
Related Vulnerabilities
The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific …
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations …
stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another …
Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers …
Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between …