Vulnerabilities (CVE)

Filtered by vendor Cdprojekt Subscribe
Filtered by product Gog Galaxy
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-56232 1 Cdprojekt 1 Gog Galaxy 2026-01-09 N/A 6.8 MEDIUM
GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.