Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-75189.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-75189
Upstream
Published
2026-01-22T03:15:47Z
Modified
2026-04-21T04:38:51.760338Z
Summary
CVE-2026-23992 affecting package gh 2.62.0-10
Details

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.

References

Affected packages

Azure Linux:3 / gh

Package

Name
gh
Purl
pkg:rpm/azure-linux/gh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.62.0-10

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-75189.json"