CVE-2025-2885
Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.7
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-1288
- Published
- 2025-03-27
- Last modified
- 2026-03-12
Affected products
- AWS tough
Weakness type
Related vulnerabilities
- CVE-2026-69793 — Windows TCP/IP Security Feature Bypass Vulnerability
- CVE-2026-18238 — OOBR in rpcap client in libpcap before 1.10.7
- CVE-2026-18794 — OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite
- CVE-2026-73219 — CVAT: Denial of service with regards to automatic annotation
- CVE-2026-18209 — Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check
- CVE-2026-15943 — Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change
- CVE-2026-42982 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- CVE-2026-14781 — Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to userinfo email