The Update Framework, through its Go implementation (go-tuf), provides a library and tooling for secure software update mechanisms, sitting deep in supply-chain workflows where its integrity is foundational to downstream trust. Its disclosed vulnerabilities cluster around cryptographic validation, path handling, and exception management—weakness classes that reflect the signature-verification and file-access criticality inherent to an update-delivery system where logic errors can undermine the security guarantees the framework is designed to provide. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Theupdateframework over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23992HIGH go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the config | Jan 22, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-23991HIGH go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF | Jan 22, 2026 | 7.5 | 28 | NO | NO |
CVE-2022-29173HIGH go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root r | May 5, 2022 | 8.8 | 22 | NO | NO |
CVE-2026-24686MEDIUM go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component wh | Jan 27, 2026 | 4.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Theupdateframework.
Media articles that mention a CVE ID that affects a product developed by Theupdateframework — matched by CVE ID, not by vendor name.