Missing Delegated Metadata Validation in awslabs/tough
Fixed in: tough 0.22.0, tuftool 0.15.0
details
- Finding IDs
- F-AWS-TOUGH-002 / F-AWS-TOUGH-003 / F-AWS-TOUGH-004 / F-AWS-TOUGH-005
- CVE
- CVE-2026-6967
- GHSA
- GHSA-4v58-8p28-2rq3
- Status
- patched
- Fixed in
- tough 0.22.0, tuftool 0.15.0
- Recorded credit
- reporter: @1seal; acknowledgement: Oleh Konko of 1seal
- Note
- GHSA-4v58-8p28-2rq3 · missing expiration, hash, and length enforcement in delegated metadata validation; includes the local metadata cache poisoning variant tracked as F-AWS-TOUGH-005
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Missing Delegated Metadata Validation in awslabs/tough
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-AWS-TOUGH-002: Verification failures. Metadata validation fails to enforce the required trust checks. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-TOUGH-002
F-AWS-TOUGH-003: Verification failures. Metadata validation fails to enforce the required trust checks. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-TOUGH-003
F-AWS-TOUGH-004: Verification failures. Metadata validation fails to enforce the required trust checks. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-TOUGH-004
F-AWS-TOUGH-005: Verification failures. Unvalidated metadata can poison the trusted local cache. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-TOUGH-005
Security area (1seal assessment): Authorization. Metadata validation fails to enforce the required trust checks. Unvalidated metadata can poison the trusted local cache. Reviewed 24 Sep 2026.