Sparkle Signing Checks Bypass
High severity GitHub Reviewed Published Feb 4, 2025 to the GitHub Advisory Database • Updated Feb 4, 2025
Description
Published by the National Vulnerability DatabaseFeb 4, 2025
Published to the GitHub Advisory Database Feb 4, 2025
Reviewed Feb 4, 2025
Last updated Feb 4, 2025
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
References