Amazon / Tough
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-6968 | Multiple Path Traversal Variants in awslabs/tough | HIGH | 7.1 | Apr 24, 2026 |
| CVE-2026-6967 | Missing Delegated Metadata Validation in awslabs/tough | HIGH | 7.1 | Apr 24, 2026 |
| CVE-2026-6966 | Signature Threshold Bypass in awslabs/tough Delegated Roles | HIGH | 7.0 | Apr 24, 2026 |
| CVE-2025-2888 | Improper timestamp caching during snapshot rollback in tough | MEDIUM | 5.7 | Mar 27, 2025 |
| CVE-2025-2887 | Failure to detect delegated target rollback in tough | MEDIUM | 5.7 | Mar 27, 2025 |
| CVE-2025-2886 | Terminating targets role delegations are not respected in tough | MEDIUM | 5.7 | Mar 27, 2025 |
| CVE-2025-2885 | Root metadata version not validated in tough | MEDIUM | 5.7 | Mar 27, 2025 |
| CVE-2021-41150 | Improper sanitization of delegated role names in tough | HIGH | 8.2 | Oct 19, 2021 |
| CVE-2021-41149 | Improper sanitization of target names in tough | HIGH | 8.2 | Oct 19, 2021 |
| CVE-2020-15093 | Improper verification of signature threshold in tough | HIGH | 8.6 | Jul 9, 2020 |
Showing 1 to 10 of 10 CVEs