theupdateframework records
5 published records for vendor theupdateframework.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-617 Reachable Assertion1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-29173No exploit | No protection against rollback attacks in go-tuftheupdateframework · go-tuf · CWE-354 | High8.8 | — | 0.6% | May 5, 2022 |
32Monitor | CVE-2024-47534No exploit | Incorrect delegation lookups can make go-tuf download the wrong artifacttheupdateframework · go-tuf · CWE-362 | High8.2 | — | 0.5% | Oct 1, 2024 |
30Monitor | CVE-2026-23991No exploit | go-tuf affected by client DoS via malformed server responsetheupdateframework · go-tuf · CWE-617 | High7.5 | — | 0.6% | Jan 21, 2026 |
30Monitor | CVE-2026-23992No exploit | go-tuf improperly validates the configured threshold for delegationstheupdateframework · go-tuf · CWE-347 | High7.5 | — | 0.2% | Jan 21, 2026 |
18Monitor | CVE-2026-24686No exploit | go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Namestheupdateframework · go-tuf · CWE-22 | Medium4.7 | — | 0.2% | Jan 26, 2026 |
- CVE-2022-2917335Monitor
No protection against rollback attacks in go-tuf
HighCVSS 8.8No exploitEPSS 1%theupdateframework · go-tufMay 5, 2022
- CVE-2024-4753432Monitor
Incorrect delegation lookups can make go-tuf download the wrong artifact
HighCVSS 8.2No exploitEPSS 1%theupdateframework · go-tufOct 1, 2024
- CVE-2026-2399130Monitor
go-tuf affected by client DoS via malformed server response
HighCVSS 7.5No exploitEPSS 1%theupdateframework · go-tufJan 21, 2026
- CVE-2026-2399230Monitor
go-tuf improperly validates the configured threshold for delegations
HighCVSS 7.5No exploitEPSS 0%theupdateframework · go-tufJan 21, 2026
- CVE-2026-2468618Monitor
go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names
MediumCVSS 4.7No exploitEPSS 0%theupdateframework · go-tufJan 26, 2026