Skip to main content

Vendor/product archive

amazon / tough CVEs

Beta · best-effort

10 CVEs tagged to amazon / tough0 Critical, 6 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-6968

Published Apr 24, 2026

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output dire…

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-6967

Published Apr 24, 2026

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing au…

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-6966

Published Apr 24, 2026

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF…

CVSS 7.0 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2025-2888

Published Mar 27, 2025

During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp v…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2887

Published Mar 27, 2025

During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the targe…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2886

Published Mar 27, 2025

Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause t…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2885

Published Mar 27, 2025

Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metada…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41150

Published Oct 19, 2021

Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize d…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41149

Published Oct 19, 2021

Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize t…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15093

Published Jul 9, 2020

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1