GHSA-846p-jg2w-w324
go-tuf affected by client DoS via malformed server response
Quick fix
GHSA-846p-jg2w-w324 — github.com/theupdateframework/go-tuf/v2: upgrade to the fixed version with the command below.
go get github.com/theupdateframework/go-tuf/v2@v2.3.1Details
# Security Disclosure: Client DoS via malformed server response
## Summary
If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic _during parsing_, causing a DoS. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key.
## Impact
Client crashes upon receiving and parsing malformed TUF metadata. This can cause long running services to enter an restart/crash loop.
## Workarounds
None currently.
## Affected code
The `metadata.checkType` function did not properly type assert the (untrusted) input causing it to panic on malformed data.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.3.1go get github.com/theupdateframework/go-tuf/v2@v2.3.1References
- https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-846p-jg2w-w324[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23991[ADVISORY]
- https://github.com/theupdateframework/go-tuf/commit/73345ab6b0eb7e59d525dac17a428f043074cef6[WEB]
- https://github.com/theupdateframework/go-tuf[PACKAGE]
- https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1[WEB]