Known Vulnerabilities for Tough by Amazon
Listed below are 6 of the newest known vulnerabilities associated with "Tough" by "Amazon".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-6968 json | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-6967 json | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allow... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-6966 json | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2021-41150 json | Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough ... | 6.5 - MEDIUM | 2021-10-19 | 2021-10-26 |
| CVE-2021-41149 json | Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough ... | 8.1 - HIGH | 2021-10-19 | 2021-10-25 |
| CVE-2020-15093 json | The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures.... | 8.6 - HIGH | 2020-07-09 | 2021-10-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Amazon | Tough | 0.7.1 | |||
| Application | Amazon | Tough | 0.7.0 | |||
| Application | Amazon | Tough | 0.6.0 | |||
| Application | Amazon | Tough | 0.5.0 | |||
| Application | Amazon | Tough | 0.4.0 | |||
| Application | Amazon | Tough | 0.3.0 | |||
| Application | Amazon | Tough | 0.2.0 | |||
| Application | Amazon | Tough | 0.1.0 | |||
| Application | Amazon | Tough | - |