We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8m7c-8m39-rv4x | awslabs/tough Delegated Roles have a Signature Threshold Bypass |
Wed, 06 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon tough Amazon tuftool |
|
| CPEs | cpe:2.3:a:amazon:tough:*:*:*:*:*:rust:*:* cpe:2.3:a:amazon:tuftool:*:*:*:*:*:rust:*:* |
|
| Vendors & Products |
Amazon
Amazon tough Amazon tuftool |
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aws
Aws tough Aws tuftool |
|
| Vendors & Products |
Aws
Aws tough Aws tuftool |
Fri, 24 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 24 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role metadata. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0. | |
| Title | Signature Threshold Bypass in awslabs/tough Delegated Roles | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-04-24T20:15:28.842Z
Reserved: 2026-04-24T16:15:44.932Z
Link: CVE-2026-6966
Updated: 2026-04-24T20:15:15.302Z
Status : Analyzed
Published: 2026-04-24T20:16:28.883
Modified: 2026-05-06T15:24:56.720
Link: CVE-2026-6966
No data.
OpenCVE Enrichment
Updated: 2026-04-28T09:17:50Z
Github GHSA