Known vulnerabilities in Go implementation of The Update Framework (TUF)

Software CPE: cpe:2.3:a:the_update_framework:go-tuf:*:*:*:*:*:*:*:*
Total vulnerabilities: 4
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Go implementation of The Update Framework (TUF) Go implementation of The Update Framework (TUF) is affected by 4 known vulnerabilities: 3 medium, 1 low Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122055 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-24686
CWE-22 Low
No
No
2.4.1 27.01.2026 SB2026012714
#VU121962 - Improper Verification of Cryptographic Signature
CVE-2026-23992
CWE-347 Medium
No
No
2.3.1 23.01.2026 SB2026012308
#VU121961 - Reachable Assertion
CVE-2026-23991
CWE-617 Medium
No
No
2.3.1 23.01.2026 SB2026012308
#VU65785 - Improper Validation of Integrity Check Value
CVE-2022-29173
CWE-354 Medium
No
No
0.3.0 26.07.2022 SB2022072617
SB2022072631