ghsa-wc9m-r3v6-9p5h

CVSS 7.3 osv_swift
Description

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "<= 2.6.3",
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-wc9m-r3v6-9p5h/GHSA-wc9m-r3v6-9p5h.json"
      },
      "package": {
        "ecosystem": "SwiftURL",
        "name": "github.com/sparkle-project/Sparkle",
        "purl": "pkg:swift/github.com/sparkle-project/Sparkle"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.6.4"
            }
          ],
          "type": "SEMVER"
        }
      ]
    }
  ],
  "aliases": [
    "BIT-java-2025-0509",
    "BIT-java-min-2025-0509",
    "BIT-jre-2025-0509",
    "CVE-2025-0509"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-02-04T23:18:58Z",
    "nvd_published_at": "2025-02-04T20:15:49Z",
    "severity": "HIGH"
  },
  "details": "A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.",
  "id": "GHSA-wc9m-r3v6-9p5h",
  "modified": "2026-09-10T03:50:06.148421015Z",
  "published": "2025-02-04T21:32:28Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0509"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sparkle-project/Sparkle/pull/2550"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/sparkle-project/Sparkle"
    },
    {
      "type": "WEB",
      "url": "https://security.netapp.com/advisory/ntap-20250124-0008"
    },
    {
      "type": "WEB",
      "url": "https://sparkle-project.org/documentation/security-and-reliability"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Sparkle Signing Checks Bypass"
}
View JSON API Download JSON