CVE-2025-41256: Cyberduck and Mountain Duck - Weak Hash Algorithm for Certificate Fingerprint
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak.
This issue affects Cyberduck: through 9.1.6; Mountain Duck: through 4.17.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41256?
CVE-2025-41256 has a medium severity due to improper TLS certificate pinning using a weak SHA-1 fingerprint.
How do I fix CVE-2025-41256?
To fix CVE-2025-41256, update Cyberduck to version 9.1.7 or later, and Mountain Duck to version 4.17.6 or later.
Which versions of Cyberduck are affected by CVE-2025-41256?
Cyberduck versions up to and including 9.1.6 are affected by CVE-2025-41256.
Which versions of Mountain Duck are affected by CVE-2025-41256?
Mountain Duck versions up to and including 4.17.5 are affected by CVE-2025-41256.
What vulnerability does CVE-2025-41256 describe?
CVE-2025-41256 describes an improper handling of TLS certificate pinning for untrusted certificates using weak SHA-1 hashing.