GHSA-fphv-w9fq-2525
Dashboard / Vulnerabilities / GHSA-fphv-w9fq-2525
GHSA-fphv-w9fq-2525
Summary: go-tuf improperly validates the configured threshold for delegations
Details: # Security Disclosure: Improper validation of configured threshold for delegations ## Summary A compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. ## Impact Unathorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. ## Patches Upgrade to v2.3.1 ## Workarounds Always make sure that the TUF metadata roles are configured with a threshold of at least 1. ## Affected code: The `metadata.VerifyDelegate` did not verify the configured threshold prior to comparison. This means that a misconfigured TUF repository could disable the signature verification by setting the threshold to 0, or a negative value (and so always make the signature threshold computation to pass).
References: https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-fphv-w9fq-2525, https://nvd.nist.gov/vuln/detail/CVE-2026-23992, https://github.com/theupdateframework/go-tuf/commit/b38d91fdbc69dfe31fe9230d97dafe527ea854a0, https://github.com/theupdateframework/go-tuf, https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1
Affected packages
Package
Name: github.com/theupdateframework/go-tuf/v2
Purl: pkg:golang/github.com/theupdateframework/go-tuf/v2
Affected ranges
Type: SEMVER
Events:
