Skip to main content

Vendor/product archive

amazon / tuftool CVEs

Beta · best-effort

3 CVEs tagged to amazon / tuftool0 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-6968

Published Apr 24, 2026

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output dire…

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-6967

Published Apr 24, 2026

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing au…

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-6966

Published Apr 24, 2026

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF…

CVSS 7.0 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1