PatchDay Alert

CVE

CVE-2025-15638

0field notes · 1digest CVSS 10.0


Daily digests

The Perl module Net::Dropbear (before 0.14) ships a bundled copy of libtomcrypt v1.18.1 or older, which carries known crypto bugs from 2016 and 2018. An attacker could exploit weaknesses in the crypto library to undermine authentication or key exchange. The CVSS 10.0 score reflects worst-case impact, but real-world risk depends on whether your app exposes Dropbear's SSH interface directly.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.