VendorsTheupdateframeworkgo-tufall versions
Vulnerabilities

Theupdateframework Go-tuf

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-29173
No protection against rollback attacks in go-tuf
Published 2022-05-05 · Modified
8.8EPSS 0.006
CVE-2026-23991
go-tuf affected by client DoS via malformed server response
Published 2026-01-22 · Analyzed
7.5EPSS 0.006
CVE-2026-23992
go-tuf improperly validates the configured threshold for delegations
Published 2026-01-22 · Analyzed
7.5EPSS 0.002
CVE-2026-24686
go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names
Published 2026-01-27 · Analyzed
4.7EPSS 0.002