go-tuf improperly validates the configured threshold for delegations
Published Jan 22, 2026
7.5
HIGHCVSS 3.1
EPSS 0.22%
Description
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.
Affected products
-
- Version >= 2.0.0, < 2.3.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Theupdateframework | GO-Tuf | n/a |
|
- ≥ 2.0.0 · < 2.3.1
No data.
OpenShift Pipelines
openshift-pipelines/pipelines-chains-controller-rhel9
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-cli-tkn-rhel9
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-opc-rhel9
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-operator-bundle
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-operator-proxy-rhel8
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-operator-proxy-rhel9
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-operator-webhook-rhel8
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-operator-webhook-rhel9
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-rhel8-operator
Fix deferred
OpenShift Pipelines
openshift-pipelines/pipelines-rhel9-operator
Fix deferred
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-central-db-rhel8
Fix deferred
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-main-rhel8
Fix deferred
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-rhel8-operator
Fix deferred
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-roxctl-rhel8
Fix deferred
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-scanner-v4-db-rhel8
Fix deferred
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-scanner-v4-rhel8
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/udi-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/client-server-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/cosign-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/gitsign-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/policy-controller-operator-bundle
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/policy-controller-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/policy-controller-rhel9-operator
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/rhtas-console-rhel9
Fix deferred
Red Hat Web Terminal
web-terminal/web-terminal-tooling-rhel9
Fix deferred
Security Profiles Operator
compliance/openshift-security-profiles-operator-bundle
Fix deferred
Security Profiles Operator
compliance/openshift-security-profiles-rhel8-operator
Fix deferred
Zero Trust Workload Identity Manager
zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9
Fix deferred
Zero Trust Workload Identity Manager
zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9
Fix deferred
Zero Trust Workload Identity Manager
zero-trust-workload-identity-manager/spiffe-spire-server-rhel9
Fix deferred
Zero Trust Workload Identity Manager - Tech Preview
zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9
Fix deferred
Zero Trust Workload Identity Manager - Tech Preview
zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9
Fix deferred
Zero Trust Workload Identity Manager - Tech Preview
zero-trust-workload-identity-manager/spiffe-spire-server-rhel9
Fix deferred
Zero Trust Workload Identity Manager - Tech Preview
zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-operator-bundle
Fix deferred
Zero Trust Workload Identity Manager - Tech Preview
zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-chains-controller-rhel9 | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel9 | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-operator-bundle | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-operator-proxy-rhel8 | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-operator-proxy-rhel9 | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-operator-webhook-rhel8 | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-operator-webhook-rhel9 | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-rhel8-operator | Fix deferred | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-rhel9-operator | Fix deferred | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-central-db-rhel8 | Fix deferred | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel8 | Fix deferred | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-rhel8-operator | Fix deferred | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-roxctl-rhel8 | Fix deferred | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-scanner-v4-db-rhel8 | Fix deferred | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-scanner-v4-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/client-server-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/cosign-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/gitsign-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/policy-controller-operator-bundle | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/policy-controller-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/policy-controller-rhel9-operator | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/rhtas-console-rhel9 | Fix deferred | n/a |
| Red Hat Web Terminal | web-terminal/web-terminal-tooling-rhel9 | Fix deferred | n/a |
| Security Profiles Operator | compliance/openshift-security-profiles-operator-bundle | Fix deferred | n/a |
| Security Profiles Operator | compliance/openshift-security-profiles-rhel8-operator | Fix deferred | n/a |
| Zero Trust Workload Identity Manager | zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9 | Fix deferred | n/a |
| Zero Trust Workload Identity Manager | zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9 | Fix deferred | n/a |
| Zero Trust Workload Identity Manager | zero-trust-workload-identity-manager/spiffe-spire-server-rhel9 | Fix deferred | n/a |
| Zero Trust Workload Identity Manager - Tech Preview | zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9 | Fix deferred | n/a |
| Zero Trust Workload Identity Manager - Tech Preview | zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9 | Fix deferred | n/a |
| Zero Trust Workload Identity Manager - Tech Preview | zero-trust-workload-identity-manager/spiffe-spire-server-rhel9 | Fix deferred | n/a |
| Zero Trust Workload Identity Manager - Tech Preview | zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-operator-bundle | Fix deferred | n/a |
| Zero Trust Workload Identity Manager - Tech Preview | zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9 | Fix deferred | n/a |
github.com/theupdateframework/go-tuf/v2
Go
Introduced 0 Fixed 2.3.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/theupdateframework/go-tuf/v2 | 0 | 2.3.1 |
Remediation
Red Hat statement
The state of a TUF repository is outside the control of the attacker prior to compromise. Following documented Red Hat guidance for repository creation will ensure that these preconditions are not present.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-23992 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2431929 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3672 Advisory
- https://github.com/advisories/GHSA-fphv-w9fq-2525 Advisory
- https://github.com/theupdateframework/go-tuf/commit/b38d91fdbc69dfe31fe9230d97dafe527ea854a0 x_refsource_MISCPatch
- https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1
- https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-fphv-w9fq-2525 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23992
- https://www.cve.org/CVERecord?id=CVE-2026-23992
Change history (0)
No recorded changes yet.