Aller au contenu

Fiche vulnérabilité

CVE-2026-23991 : faille élevée theupdateframework go-tuf (CVSS 7.5)

Description

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
22 janv. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • theupdateframework go-tuf

Références

Rechercher une autre vulnérabilité dans la base CVE