Security: theupdateframework/go-tuf
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
go-tuf TAP 4 multirepo repoName path traversal escapes local metadata cache directoryGHSA-jqc5-w2xx-5vq4 published
Jan 26, 2026 by rdimitrovModerate -
Client DoS via malformed server responseGHSA-846p-jg2w-w324 published
Jan 20, 2026 by kommendorkaptenModerate -
Improper validation of configured threshold for delegationsGHSA-fphv-w9fq-2525 published
Jan 20, 2026 by kommendorkaptenModerate -
Incorrect delegation lookups can make go-tuf download the wrong artifactGHSA-4f8r-qqr9-fq8j published
Oct 1, 2024 by rdimitrovHigh -
Improper handling of different key IDs for the same public keys in attacker-controlled metadataGHSA-3633-5h82-39pq published
Sep 8, 2022 by joshuaglLow -
No protection against rollback attacks for roles other than rootGHSA-66x3-6cw3-v5gj published
May 5, 2022 by joshuaglHigh