Vulnerability Description
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sparkle-Project | Sparkle | < 2.6.4 |
| Netapp | Hci Compute Node | - |
| Netapp | Oncommand Workflow Automation | - |
Related Weaknesses (CWE)
References
- https://github.com/sparkle-project/Sparkle/pull/2550Issue TrackingPatch
- https://sparkle-project.org/documentation/security-and-reliability/Patch
- https://security.netapp.com/advisory/ntap-20250124-0008/Vendor Advisory
FAQ
What is CVE-2025-0509?
CVE-2025-0509 is a vulnerability with a CVSS score of 7.3 (HIGH). A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
How severe is CVE-2025-0509?
CVE-2025-0509 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0509?
Check the references section above for vendor advisories and patch information. Affected products include: Sparkle-Project Sparkle, Netapp Hci Compute Node, Netapp Oncommand Workflow Automation.