Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-23991

7 месяцев назад

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-23991

7 месяцев назад

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-23991

7 месяцев назад

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-23991

7 месяцев назад

go-tuf is a Go implementation of The Update Framework (TUF). Starting ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-846p-jg2w-w324

7 месяцев назад

go-tuf affected by client DoS via malformed server response

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2026-01060

7 месяцев назад

Уязвимость функции metadata.checkType() фреймворка для обеспечения безопасности систем обновления программного обеспечения go-tuf, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20386-1

5 месяцев назад

Security update for cosign

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0777-1

6 месяцев назад

Security update for cosign

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-23991

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

CVSS3: 5.9
1%
Низкий
7 месяцев назад
redhat логотип
CVE-2026-23991

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

CVSS3: 5.9
1%
Низкий
7 месяцев назад
nvd логотип
CVE-2026-23991

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

CVSS3: 5.9
1%
Низкий
7 месяцев назад
debian логотип
CVE-2026-23991

go-tuf is a Go implementation of The Update Framework (TUF). Starting ...

CVSS3: 5.9
1%
Низкий
7 месяцев назад
github логотип
GHSA-846p-jg2w-w324

go-tuf affected by client DoS via malformed server response

CVSS3: 5.9
1%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-01060

Уязвимость функции metadata.checkType() фреймворка для обеспечения безопасности систем обновления программного обеспечения go-tuf, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
1%
Низкий
7 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20386-1

Security update for cosign

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0777-1

Security update for cosign

6 месяцев назад

Уязвимостей на страницу