CVE Vulnerabilities

CVE-2025-67109

Improper Validation of Certificate Expiration

Published: Dec 23, 2025 | Modified: Jan 06, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.

Weakness

A certificate expiration is not validated or is incorrectly validated, so trust may be assigned to certificates that have been abandoned due to age.

Affected Software

NameVendorStart VersionEnd Version
Cyclone_data_distribution_serviceEclipse*0.10.5 (excluding)

Potential Mitigations

References