GHSA-846p-jg2w-w324

    Dashboard / Vulnerabilities / GHSA-846p-jg2w-w324

    GHSA-846p-jg2w-w324

    Published: 21 Jan 2026Last Modified: 10 Sept 2026

    Summary: go-tuf affected by client DoS via malformed server response

    Details: # Security Disclosure: Client DoS via malformed server response ## Summary If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic _during parsing_, causing a DoS. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. ## Impact Client crashes upon receiving and parsing malformed TUF metadata. This can cause long running services to enter an restart/crash loop. ## Workarounds None currently. ## Affected code The `metadata.checkType` function did not properly type assert the (untrusted) input causing it to panic on malformed data.

    Affected packages

    Package

    Name: github.com/theupdateframework/go-tuf/v2

    Purl: pkg:golang/github.com/theupdateframework/go-tuf/v2

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High