2026-019-AWS
Issues in tough library and tuftool CLI utility
🔗 CVE IDs covered (3)
📋 Description
Bulletin ID: 2026-019-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/24 13:30 AM PDT
Description:
Multiple security issues have been identified in the tough library and tuftool CLI utility. tough is a Rust library used for generating, signing, and managing TUF (The Update Framework) repositories, and tuftool is the command-line interface for repository management Operations.
The following issues have been identified: - CVE-2026-6966 - CVE-2026-6967 - CVE-2026-6968
Impacted versions: - tough: versions 0.1.0 through 0.21.x (inclusive) - tuftool: versions 0.1.0 through 0.14.x (inclusive)
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.