CVE-2025-2885 Details
Description
Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
A vulnerability exists in the Tough library, specifically in versions prior to 0.20.0, due to inadequate validation of the root metadata version number. This flaw could enable an actor to send an arbitrary version number to the client, instead of the correct one, potentially altering the version that the client retrieves. As a result, the Tough client might trust outdated or improperly signed metadata, leading to incorrect content being fetched from a TUF repository.
Users are advised to upgrade to Tough version 0.20.0 or later. If using forked or derivative code, ensure it is patched to include the latest fixes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/AWS-2025-007/ | AMZN | Vendor Advisory |
| https://github.com/awslabs/tough/releases/tag/tough-v0.20.0 | AMZN | |
| https://github.com/awslabs/tough/security/advisories/GHSA-5vmp-m5v2-hx47 | AMZN | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1288 | Improper Validation of Consistency within Input | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon tough | < 0.20.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | CVE Modified | AMZN |
| Sep 19, 2025 | Initial Analysis | [email protected] |
| Mar 27, 2025 | New CVE Received | AMZN |