VendorsAmazontoughany version
Vulnerabilities

Amazon Tough any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2020-15093
Improper verification of signature threshold in tough
Published 2020-07-09 · Modified
8.6EPSS 0.014
CVE-2021-41149
Improper sanitization of target names in tough
Published 2021-10-19 · Modified
8.5EPSS 0.011
CVE-2021-41150
Improper sanitization of delegated role names in tough
Published 2021-10-19 · Modified
8.2EPSS 0.013
CVE-2026-6968
Multiple Path Traversal Variants in awslabs/tough
Published 2026-04-24 · Analyzed
7.1EPSS 0.006
CVE-2026-6967
Missing Delegated Metadata Validation in awslabs/tough
Published 2026-04-24 · Analyzed
7.1EPSS 0.003
CVE-2026-6966
Signature Threshold Bypass in awslabs/tough Delegated Roles
Published 2026-04-24 · Analyzed
7.0EPSS 0.004
CVE-2025-2885
Root metadata version not validated in tough
Published 2025-03-27 · Modified
5.7EPSS 0.003
CVE-2025-2886
Terminating targets role delegations are not respected in tough
Published 2025-03-27 · Modified
5.7EPSS 0.003
CVE-2025-2887
Failure to detect delegated target rollback in tough
Published 2025-03-27 · Modified
5.7EPSS 0.003
CVE-2025-2888
Improper timestamp caching during snapshot rollback in tough
Published 2025-03-27 · Modified
5.7EPSS 0.003