CVE-2025-41256 Details
Description
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak. This issue affects Cyberduck: through 9.1.6; Mountain Duck: through 4.17.5.
A vulnerability exists in Cyberduck versions prior to 9.1.6 and Mountain Duck versions prior to 4.17.5, due to improper handling of TLS certificate pinning for untrusted certificates, such as self-signed ones. The issue arises because the certificate fingerprint is stored using SHA-1, a weak hash algorithm, instead of a more secure option like SHA-256 or SHA-512. This flaw could allow an attacker to create a hash collision, facilitating a man-in-the-middle attack on the TLS-encrypted connection and resulting in a complete loss of confidentiality and integrity.
Users are advised to update to Cyberduck version 9.1.7 or Mountain Duck version 4.17.6, both of which address this vulnerability by using a stronger hashing algorithm for certificate fingerprints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2025CISA-ADP
Assessed Jun 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/iterate-ch/cyberduck/security/advisories/GHSA-688c-vjrc-84rv | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20250325-02_Cyberduck_Mountain_Duck_Weak_Hash | CISA-ADP | AdvisoryBroken Link |
| https://github.com/iterate-ch/cyberduck/security/advisories/GHSA-688c-vjrc-84rv | sba-research | AdvisoryExploitRemedyVendor |
| https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20250325-02_Cyberduck_Mountain_Duck_Weak_Hash | sba-research | AdvisoryBroken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-328 | Use of Weak Hash | sba-research |
Affected Products
| Product | Versions |
|---|---|
| iterate Cyberduck | <= 9.1.6 (semver) |
CPE
Remediation
| |
| iterate Mountain Duck | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | sba-research |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | New CVE Received | sba-research |
Volerion