AWS Vulnerabilities and Affected Products
Vulnerabilities associated with tuftool.
Products
Clear product- FreeRTOS-Plus-TCP7 vulnerabilities
- tough7 vulnerabilities
- Kiro IDE5 vulnerabilities
- AWS-LC4 vulnerabilities
- Research and Engineering Studio (RES)4 vulnerabilities
- AWS Ops Wheel3 vulnerabilities
- aws-cdk3 vulnerabilities
- Opensearch3 vulnerabilities
- tuftool3 vulnerabilities
- AWS Advanced JDBC Wrapper2 vulnerabilities
- AWS Serverless Application Model Command Line Interface2 vulnerabilities
- AWS-LC-FIPS2 vulnerabilities
- aws-sdk-cpp2 vulnerabilities
- bedrock-agentcore2 vulnerabilities
- Client VPN2 vulnerabilities
- Firecracker2 vulnerabilities
- SageMaker Python SDK2 vulnerabilities
- sagemaker-python-sdk2 vulnerabilities
- strands-agents-tools2 vulnerabilities
- AgentCore CLI1 vulnerability
- Amazon Bedrock AgentCore harness1 vulnerability
- Amazon Braket Python SDK1 vulnerability
- Amazon CloudFront1 vulnerability
- Amazon ECS Agent1 vulnerability
- Amazon Redshift connector for Python1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-6968HIGH | Multiple Path Traversal Variants in awslabs/toughIncomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked metadata filenames in SignedRole::write, because write paths trust the joined destination path without post-resolution containment verification. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.… CWE-22Apr 24, 2026 | CVSS7.1v4.0 | EPSS0.52% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6967HIGH | Missing Delegated Metadata Validation in awslabs/toughMissing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, because load_delegations does not apply the same validation checks as the top-level targets metadata path. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0. CWE-345Apr 24, 2026 | CVSS7.1v4.0 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6966HIGH | Signature Threshold Bypass in awslabs/tough Delegated RolesImproper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role metadata. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0. CWE-347Apr 24, 2026 | CVSS7.0v4.0 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |