github.com/theupdateframework/go-tuf/v2
Activity
- Latest release
- 3mo ago
- Total releases
- 11
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Stars
- —
Details
- First release
- Jul 16, 2024
| Version | Released | |
|---|---|---|
v2.4.2
patch
|
v2.4.2
patch
Dependencies (6)
|
|
v2.4.1
patch
|
v2.4.1
patch
Dependencies (6)
|
|
v2.4.0
minor
1 CVE
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.4.0
minor
Dependencies (6)
|
|
v2.3.1
patch
1 CVE
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.3.1
patch
Dependencies (6)
|
|
v2.3.0
minor
3 CVEs
CVE-2026-23991
GO-2026-4348
GHSA-846p-jg2w-w324
Feb 02, 2026
Client DoS via malformed server response in github.com/theupdateframework/go-tuf Client DoS via malformed server response in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-23992
GO-2026-4349
GHSA-fphv-w9fq-2525
Feb 02, 2026
Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.3.0
minor
Dependencies (6)
|
|
v2.2.0
minor
3 CVEs
CVE-2026-23991
GO-2026-4348
GHSA-846p-jg2w-w324
Feb 02, 2026
Client DoS via malformed server response in github.com/theupdateframework/go-tuf Client DoS via malformed server response in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-23992
GO-2026-4349
GHSA-fphv-w9fq-2525
Feb 02, 2026
Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.2.0
minor
Dependencies (6)
|
|
v2.1.1
patch
3 CVEs
CVE-2026-23991
GO-2026-4348
GHSA-846p-jg2w-w324
Feb 02, 2026
Client DoS via malformed server response in github.com/theupdateframework/go-tuf Client DoS via malformed server response in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-23992
GO-2026-4349
GHSA-fphv-w9fq-2525
Feb 02, 2026
Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (6)
|
|
v2.1.0
minor
3 CVEs
CVE-2026-23991
GO-2026-4348
GHSA-846p-jg2w-w324
Feb 02, 2026
Client DoS via malformed server response in github.com/theupdateframework/go-tuf Client DoS via malformed server response in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-23992
GO-2026-4349
GHSA-fphv-w9fq-2525
Feb 02, 2026
Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (6)
|
|
v2.0.2
patch
3 CVEs
CVE-2026-23991
GO-2026-4348
GHSA-846p-jg2w-w324
Feb 02, 2026
Client DoS via malformed server response in github.com/theupdateframework/go-tuf Client DoS via malformed server response in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-23992
GO-2026-4349
GHSA-fphv-w9fq-2525
Feb 02, 2026
Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.0.2
patch
Dependencies (5)
|
|
v2.0.1
patch
3 CVEs
CVE-2026-23991
GO-2026-4348
GHSA-846p-jg2w-w324
Feb 02, 2026
Client DoS via malformed server response in github.com/theupdateframework/go-tuf Client DoS via malformed server response in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-23992
GO-2026-4349
GHSA-fphv-w9fq-2525
Feb 02, 2026
Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.0.1
patch
Dependencies (5)
|
|
v2.0.0
initial
4 CVEs
CVE-2026-23991
GO-2026-4348
GHSA-846p-jg2w-w324
Feb 02, 2026
Client DoS via malformed server response in github.com/theupdateframework/go-tuf Client DoS via malformed server response in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2026-24686
GO-2026-4377
GHSA-jqc5-w2xx-5vq4
Feb 02, 2026
Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf Fixed in
2.4.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-23992
GO-2026-4349
GHSA-fphv-w9fq-2525
Feb 02, 2026
Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf Fixed in
2.3.1
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2024-47534
GO-2024-3166
GHSA-4f8r-qqr9-fq8j
Oct 09, 2024
Incorrect delegation lookups can make go-tuf download the wrong artifact in github.com/theupdateframework/go-tuf Incorrect delegation lookups can make go-tuf download the wrong artifact in github.com/theupdateframework/go-tuf Fixed in
2.0.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0
initial
Dependencies (5)
|