CVE-2026-23992
MEDIUMgo-tuf 2.0.0-2.3.0 - Improper Verification of Cryptographic Signature
Title source: llmDescription
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-fphv-w9fq-2525
Scores
CVSS v3
5.9
EPSS
0.0020
EPSS Percentile
9.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-347
Status
published
Products (2)
theupdateframework/go-tuf
0 - 2.3.1Go
theupdateframework/go-tuf
2.0.0 - 2.3.1
Published
Jan 22, 2026
Tracked Since
Feb 18, 2026