CVE-2025-2885 — Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the — CVE Database · The Intelligence Room