Логотип exploitDog
bind:CVE-2026-23992
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23992

Количество 5

Количество 5

ubuntu логотип

CVE-2026-23992

18 дней назад

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-23992

18 дней назад

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-23992

18 дней назад

go-tuf is a Go implementation of The Update Framework (TUF). Starting ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-fphv-w9fq-2525

18 дней назад

go-tuf improperly validates the configured threshold for delegations

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2026-01059

21 день назад

Уязвимость функции metadata.VerifyDelegate() фреймворка для обеспечения безопасности систем обновления программного обеспечения go-tuf, позволяющая нарушителю получить доступ на чтение и изменение данных

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-23992

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.

CVSS3: 5.9
0%
Низкий
18 дней назад
nvd логотип
CVE-2026-23992

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.

CVSS3: 5.9
0%
Низкий
18 дней назад
debian логотип
CVE-2026-23992

go-tuf is a Go implementation of The Update Framework (TUF). Starting ...

CVSS3: 5.9
0%
Низкий
18 дней назад
github логотип
GHSA-fphv-w9fq-2525

go-tuf improperly validates the configured threshold for delegations

CVSS3: 5.9
0%
Низкий
18 дней назад
fstec логотип
BDU:2026-01059

Уязвимость функции metadata.VerifyDelegate() фреймворка для обеспечения безопасности систем обновления программного обеспечения go-tuf, позволяющая нарушителю получить доступ на чтение и изменение данных

CVSS3: 5.9
0%
Низкий
21 день назад

Уязвимостей на страницу