CVE-2026-23992

Source
https://cve.org/CVERecord?id=CVE-2026-23992
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23992.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23992
Aliases
Downstream
Related
Published
2026-01-22T02:20:06.845Z
Modified
2026-01-28T05:53:09.238127Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
go-tuf improperly validates the configured threshold for delegations
Details

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.

Database specific
{
    "cwe_ids": [
        "CWE-347"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23992.json"
}
References

Affected packages

Git / github.com/theupdateframework/go-tuf

Affected ranges

Type
GIT
Repo
https://github.com/theupdateframework/go-tuf
Events

Affected versions

v2.*

v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.2.0
v2.3.0

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23992.json"