CVE-2025-0509: Netapp Hci Compute Node
Medium severity, CVSS 6.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
Affected products
- Netapp Hci Compute Node: affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Sparkle-Project Sparkle: before 2.6.4 (fixed in 2.6.4)
Published 2025-02-04. Last modified 2026-06-17.