Skip to content
Noroxi

theupdateframework records

5 published records for vendor theupdateframework.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

5 records
  • No protection against rollback attacks in go-tuf

    HighCVSS 8.8No exploitEPSS 1%

    theupdateframework · go-tufMay 5, 2022

  • Incorrect delegation lookups can make go-tuf download the wrong artifact

    HighCVSS 8.2No exploitEPSS 1%

    theupdateframework · go-tufOct 1, 2024

  • go-tuf affected by client DoS via malformed server response

    HighCVSS 7.5No exploitEPSS 1%

    theupdateframework · go-tufJan 21, 2026

  • go-tuf improperly validates the configured threshold for delegations

    HighCVSS 7.5No exploitEPSS 0%

    theupdateframework · go-tufJan 21, 2026

  • go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names

    MediumCVSS 4.7No exploitEPSS 0%

    theupdateframework · go-tufJan 26, 2026