GHSA-fphv-w9fq-2525
go-tuf improperly validates the configured threshold for delegations
Quick fix
GHSA-fphv-w9fq-2525 — github.com/theupdateframework/go-tuf/v2: upgrade to the fixed version with the command below.
go get github.com/theupdateframework/go-tuf/v2@v2.3.1Details
# Security Disclosure: Improper validation of configured threshold for delegations
## Summary
A compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification.
## Impact
Unathorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made.
## Patches
Upgrade to v2.3.1
## Workarounds
Always make sure that the TUF metadata roles are configured with a threshold of at least 1.
## Affected code:
The `metadata.VerifyDelegate` did not verify the configured threshold prior to comparison. This means that a misconfigured TUF repository could disable the signature verification by setting the threshold to 0, or a negative value (and so always make the signature threshold computation to pass).
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.3.1go get github.com/theupdateframework/go-tuf/v2@v2.3.1References
- https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-fphv-w9fq-2525[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23992[ADVISORY]
- https://github.com/theupdateframework/go-tuf/commit/b38d91fdbc69dfe31fe9230d97dafe527ea854a0[WEB]
- https://github.com/theupdateframework/go-tuf[PACKAGE]
- https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1[WEB]