Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2185823
AlmaLinux
5878
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17153
BellSoft Hardened Containers
744
Bitnami
9227
Chainguard
1020158
CleanStart
3450
CRAN
14
crates.io
2720
Debian
67390
Echo
6546
GHC
3
GIT
106529
GitHub Actions
55
Go
9157
Hackage
32
Hex
353
Julia
1713
Linux
29368
Mageia
6203
Maven
6998
MinimOS
142936
npm
228510
NuGet
1860
opam
29
openEuler
8674
openSUSE
14332
OSS-Fuzz
4006
Packagist
7036
Pub
11
PyPI
25079
Red Hat
23183
Rocky Linux
4240
Root
19478
RubyGems
4709
SUSE
23047
SwiftURL
59
TuxCare
9237
Ubuntu
64508
VSCode
21
Wolfi
287393
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qp9x-wp8f-qgjj
PyPI/tuf
tuf has platform-dependent delegation path matching
28 May
Fix available
Severity - 4.0 (Medium)
GHSA-77hh-43cm-v8j6
PyPI/tuf
tuf's Metadata API: Targets.get_delegated_role() is missing input validation
16 Feb 2024
Fix available
GHSA-r7vq-6425-j94w
PyPI/tuf
Python-TUF vulnerable to incorrect threshold signature computation for new root metadata
15 Sep 2022
Fix available
GHSA-wjw6-2cqr-j4qr
PyPI/tuf
Client metadata path-traversal
19 Oct 2021
Fix available
Severity - 6.9 (Medium)
PYSEC-2021-376
PyPI/tuf
github.com/theupdateframework/python-tuf
See record for full details
19 Oct 2021
Fix available
PYSEC-2020-145
PyPI/tuf
github.com/theupdateframework/tuf
See record for full details
09 Sep 2020
Fix available
GHSA-f8mr-jv2c-v8mg
PyPI/tuf
Invalid root may become trusted root in The Update Framework (TUF)
09 Sep 2020
Fix available
Severity - 6.3 (Medium)
GHSA-2828-9vh6-9m6j
PyPI/tuf
Client Denial of Service on TUF
21 Aug 2020
Fix available
Severity - 6.9 (Medium)
GHSA-pwqf-9h7j-7mv8
PyPI/tuf
Incorrect threshold signature computation in TUF
21 Aug 2020
Fix available
Severity - 9.3 (Critical)
PYSEC-2020-147
PyPI/tuf
See record for full details
05 Feb 2020
Fix available
PYSEC-2020-146
PyPI/tuf
See record for full details
14 Jan 2020
Fix available
PyPI - OSV