CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Debian.
CVE
CVE-2025-8454
Severity
CRITICAL
CVSS
9.8
EPSS
0.24%
Debian
Original NVD Description
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.
Related CVEs
Other vulnerabilities affecting the same vendor(s)