CVE-2026-24686
- EPSS 0.01%
- Veröffentlicht 27.01.2026 00:45:43
- Zuletzt bearbeitet 24.02.2026 19:08:46
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2...
CVE-2026-23992
- EPSS 0.01%
- Veröffentlicht 22.01.2026 02:20:06
- Zuletzt bearbeitet 17.02.2026 16:02:19
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disable...
CVE-2026-23991
- EPSS 0.02%
- Veröffentlicht 22.01.2026 02:16:37
- Zuletzt bearbeitet 17.02.2026 16:10:55
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the clie...
CVE-2024-47534
- EPSS 0.34%
- Veröffentlicht 01.10.2024 16:15:09
- Zuletzt bearbeitet 21.11.2024 17:15:17
go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the o...
CVE-2022-29173
- EPSS 0.13%
- Veröffentlicht 05.05.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:58:38
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, checks for rollback attacks are not implemented cor...