CVE-2026-6967Disclosure(amazon / tough)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, because load_delegations does not apply the same validation checks as the top-level targets metadata path. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tough
  • tuftool

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-21)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
toughtuftool

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-21: 2Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-21: 104-2404-2505-21
Signal classification1 categories
Disclosure
4100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-05-212
Disclosure2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-6967: Metadata Integrity Bypass (CVSS 5.9) CWE-345: Insufficient Verification of Data Authenticity TL;DR AWS's awslabs/tough library—the Rust implementation of The Update Framework (TUF) standard—has three vulnerabilities that allow authenticated attackers to…

    Post summary

    The text announces three metadata integrity bypass vulnerabilities in AWS's TUF implementation, noting a CVSS 5.9 score and CWE-345, but does not discuss exploitation, tool availability, or patches.

    1000038
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Foundation Cracked: AWS tough Library Breaks TUF Metadata Integrity (CVE-2026-6967, CVE-2026-6966, CVE-2026-6968). TL;DR AWS's awslabs/tough library—the Rust implementation of The Update Framework (TUF) standard—has three vulnerabilities that allow authenticated…

    Post summary

    The post announces three newly identified CVEs in AWS’s tough library, marking a vulnerability disclosure with minimal technical detail.

    1000053
    227 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6967 Delegated Metadata Validation Bypass in awslabs/tough Before v0.22.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6967

    Post summary

    The text announces CVE-2026-6967, noting a delegated metadata validation bypass in awslabs/tough before v0.22.0, with a link to a vulnerability database but no exploit or remediation details.

    0000037
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6967 Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated… https://www.cve.org/CVERecord?id=CVE-2026-6967

    Post summary

    The post announces CVE-2026-6967, noting missing validation checks in awslabs/tough and that it allows remote authenticated users to exploit the flaw; no PoC, exploit tool, active exploitation, patch, or debunking claim is provided.

    0000067
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appamazontough-rust-
Appamazontuftool-rust-

Explore more