Tough
Vendor:
First CVE: Jul 9, 2020 · Active for 6 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tough over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 9, 2020
6 years ago
Most Recent CVE
Apr 24, 2026
94 days ago
CVE Severity & Scoring
Tough10 CVEs
80%
20%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low5 (50.0%)
High4 (40.0%)
None1 (10.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15093HIGH The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature i | Jul 9, 2020 | 8.6 | 27 | NO | NO |
CVE-2021-41149HIGH Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize ta | Oct 19, 2021 | 8.1 | 25 | NO | NO |
CVE-2026-6966MEDIUM Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF s | Apr 24, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-6968MEDIUM Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output direc | Apr 24, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-6967MEDIUM Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing aut | Apr 24, 2026 | 6.5 | 23 | NO | NO |
CVE-2021-41150MEDIUM Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize de | Oct 19, 2021 | 6.5 | 21 | NO | NO |
CVE-2025-2887MEDIUM During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target | Mar 27, 2025 | 4.5 | 18 | NO | NO |
CVE-2025-2885MEDIUM Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadat | Mar 27, 2025 | 4.5 | 16 | NO | NO |
CVE-2025-2888MEDIUM During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp va | Mar 27, 2025 | 4.5 | 15 | NO | NO |
CVE-2025-2886MEDIUM Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause th | Mar 27, 2025 | 4.5 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Tough
Top CWEs
Versions
No cataloged versions.