CVE-2025-7954
published 2025-08-06CVE-2025-7954: A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher…
PriorityP346high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.38%
30.0th percentile
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopware | platform | 0 – 6.6.10.4 | — |
| shopware | shopware | — | — |
| shopware | shopware | — | — |
| shopware | shopware | >= 6.6.0.0 < 6.7.2.0 | 6.7.2.0 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X
osv9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libtasn1-6 vulnerabilities
osv·2026-02-10·CVSS 9.1
CVE-2021-46848 libtasn1-6 vulnerabilities
libtasn1-6 vulnerabilities
USN-7954-1 fixed vulnerabilities in Libtasn1. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. CVE-2021-46848 only affected Ubuntu
14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Libtasn1 incorrectly handled decoding ASN.1
content. An attacker could possibly use this issue to cause Libtasn1 to
crash, resulting in a denial of service. (CVE-2025-13151)
It was discovered that Libtasn1 incorrectly handled encoding ASN.1
content. An attacker could possibly use this issue to cause Libtasn1 to
crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS. (CVE-2021-46848)
GHSA
Shopware race condition bypasses voucher restrictions
ghsa·2025-08-06
CVE-2025-7954 [MEDIUM] CWE-362 Shopware race condition bypasses voucher restrictions
Shopware race condition bypasses voucher restrictions
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
OSV
Shopware race condition bypasses voucher restrictions
osv·2025-08-06
CVE-2025-7954 [MEDIUM] Shopware race condition bypasses voucher restrictions
Shopware race condition bypasses voucher restrictions
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-06
Published