Known Vulnerabilities for Tuftool by AWS
Listed below are 3 of the newest known vulnerabilities associated with "Tuftool" by "AWS".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-6968 json | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-6967 json | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allow... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-6966 json | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.... | Not Provided | 2026-04-24 | 2026-04-24 |