CVE Database
/

CVE-2025-8454

Back to search

CVE-2025-8454

Published: Aug 1, 2025

Modified: Aug 1, 2025

PUBLISHED

Description

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.

VendorProductVersions

Debian

devscripts

affected
0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now