CVE-2025-67825 Details
Description
An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer information consistently reflects the verified certificate identity.
A vulnerability exists in Nitro PDF Pro for Windows, prior to version 14.42.0.34, where the application may display signer information from an unverified PDF field instead of the verified certificate subject. This issue can lead to inconsistencies in signer details within documents. The display logic has been updated in version 14.42.0.34 to ensure that signer information accurately reflects the verified certificate identity.
Users can upgrade to Nitro PDF Pro for Windows version 14.42.0.34 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gonitro.com | [email protected] | Product |
| https://www.gonitro.com/documentation/release-notes | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| gonitro nitro pdf pro | < 14.42.0.34 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 2, 2026 | CVE Modified | CISA-ADP |
| Jan 26, 2026 | Initial Analysis | [email protected] |
| Jan 9, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2026 | New CVE Received | [email protected] |