VYPR

GoSign Desktop

by GoSign Desktop

CVEs (2)

  • CVE-2025-34324HigNov 18, 2025
    risk 0.51cvss 7.8epss 0.00

    GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs and SHA-256 hashes but is not digitally signed, so its authenticity relies solely on the underlying TLS channel. In affected…

  • CVE-2025-65083LowNov 17, 2025
    risk 0.21cvss 3.2epss 0.00

    GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Desktop user selects an arbitrary proxy server without consideration of whether outbound HTTPS connections from the proxy server to…