CVE-2026-23991

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:theupdateframework:go-tuf:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) go-tuf es una implementación en Go de The Update Framework (TUF). A partir de la versión 2.0.0 y antes de la versión 2.3.1, si el repositorio TUF (o cualquiera de sus espejos) devuelve JSON de metadatos TUF no válido (JSON válido pero metadatos TUF no bien formados), el cliente entrará en pánico durante el análisis, causando una denegación de servicio. El pánico ocurre antes de que se valide cualquier firma. Esto significa que un repositorio/espejo/caché comprometido puede DoS a los clientes sin tener acceso a ninguna clave de firma. La versión 2.3.1 soluciona el problema. No hay soluciones alternativas conocidas disponibles.

17 Feb 2026, 16:10

Type Values Removed Values Added
CPE cpe:2.3:a:theupdateframework:go-tuf:*:*:*:*:*:*:*:*
First Time Theupdateframework go-tuf
Theupdateframework
References () https://github.com/theupdateframework/go-tuf/commit/73345ab6b0eb7e59d525dac17a428f043074cef6 - () https://github.com/theupdateframework/go-tuf/commit/73345ab6b0eb7e59d525dac17a428f043074cef6 - Patch
References () https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1 - () https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1 - Release Notes
References () https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-846p-jg2w-w324 - () https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-846p-jg2w-w324 - Vendor Advisory

22 Jan 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 03:15

Updated : 2026-06-17 10:22


NVD link : CVE-2026-23991

Mitre link : CVE-2026-23991

CVE.ORG link : CVE-2026-23991


JSON object : View

Products Affected

theupdateframework

  • go-tuf
CWE
CWE-617

Reachable Assertion

CWE-754

Improper Check for Unusual or Exceptional Conditions