CVE Vulnerabilities

CVE-2025-66422

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Nov 30, 2025 | Modified: Dec 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

Affected Software

NameVendorStart VersionEnd Version
TrytondTryton6.0.0 (including)6.0.70 (excluding)
TrytondTryton7.0.0 (including)7.0.40 (excluding)
TrytondTryton7.4.0 (including)7.4.21 (excluding)
TrytondTryton7.6.0 (including)7.6.11 (excluding)
Tryton-serverUbuntuplucky*
Tryton-serverUbuntuupstream*

References