We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4v58-8p28-2rq3 | awslabs/tough is Missing Delegated Metadata Validation |
Wed, 06 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon tough Amazon tuftool |
|
| CPEs | cpe:2.3:a:amazon:tough:*:*:*:*:*:rust:*:* cpe:2.3:a:amazon:tuftool:*:*:*:*:*:rust:*:* |
|
| Vendors & Products |
Amazon
Amazon tough Amazon tuftool |
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aws
Aws tough Aws tuftool |
|
| Vendors & Products |
Aws
Aws tough Aws tuftool |
Fri, 24 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 24 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, because load_delegations does not apply the same validation checks as the top-level targets metadata path. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0. | |
| Title | Missing Delegated Metadata Validation in awslabs/tough | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-04-24T20:13:20.016Z
Reserved: 2026-04-24T16:15:46.781Z
Link: CVE-2026-6967
Updated: 2026-04-24T20:13:08.897Z
Status : Analyzed
Published: 2026-04-24T20:16:29.020
Modified: 2026-05-06T15:32:38.257
Link: CVE-2026-6967
No data.
OpenCVE Enrichment
Updated: 2026-04-28T09:17:49Z
Github GHSA