Improper validation of configured threshold for delegations
Fixed in: go-tuf/v2 2.3.1
details
- Finding IDs
- F-TUF-001
- CVE
- CVE-2026-23992
- GHSA
- GHSA-fphv-w9fq-2525
- Status
- patched
- Fixed in
- go-tuf/v2 2.3.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Improper validation of configured threshold for delegations
- Upstream CWE
- CWE-347
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: remediation_reviewer (accepted)
F-TUF-001: Verification failures. Delegated signature threshold enforcement is incomplete. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TUF-001
Security area (1seal assessment): Authorization. The delegated role can be accepted without the configured number of authorized signatures; this weakens the metadata authorization policy. Reviewed 24 Sep 2026.