Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0232 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. |
Github GHSA |
GHSA-wc9m-r3v6-9p5h | Sparkle Signing Checks Bypass |
Tue, 05 Aug 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp hci Compute Node Netapp oncommand Workflow Automation Sparkle-project Sparkle-project sparkle |
|
| CPEs | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* cpe:2.3:a:sparkle-project:sparkle:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netapp
Netapp hci Compute Node Netapp oncommand Workflow Automation Sparkle-project Sparkle-project sparkle |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 17 Feb 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was found in Sparkle before version 2.64. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was found in Sparkle before version 2.64. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | |
| Title | Signing Checks Bypass | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-02-17T12:03:46.428Z
Reserved: 2025-01-15T21:25:14.312Z
Link: CVE-2025-0509
Updated: 2025-02-04T20:02:51.557Z
Status : Analyzed
Published: 2025-02-04T20:15:49.763
Modified: 2025-08-05T14:35:15.903
Link: CVE-2025-0509
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA