CVE-2025-41256

Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak. This issue affects Cyberduck: through 9.1.6; Mountain Duck: through 4.17.5.
Configurations

No configuration.

History

26 Jun 2025, 18:57

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-25 10:15

Updated : 2025-06-26 18:57


NVD link : CVE-2025-41256

Mitre link : CVE-2025-41256

CVE.ORG link : CVE-2025-41256


JSON object : View

Products Affected

No product.

CWE
CWE-328

Use of Weak Hash