awslabs
Security Risk Profile
32
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 27, 2025 to present
4
Total CVEs
3
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
32/100
low
Severity Distribution
Critical
0High
3Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
4Age Distribution
Common Weaknesses (CWE)
1
Path Traversal
1
Most Affected Products
1. awslabs tough4
2. Amazon Tough Rust4
3. awslabs tuftool3
4. Amazon Tuftool Rust3
5. rust/tough3
Recent Vulnerabilities
See more →CVE-2026-6968
CVSS 7.1EPSS 0%high
Multiple Path Traversal Variants in awslabs/tough
4/24/2026🔧 No Patch
CVE-2026-6967
CVSS 7.1EPSS 0%high
Missing Delegated Metadata Validation in awslabs/tough
4/24/2026
CVE-2026-6966
CVSS 7.0EPSS 0%high
Signature Threshold Bypass in awslabs/tough Delegated Roles
4/24/2026
CVE-2025-2885
CVSS 5.7EPSS 0%medium
Root metadata version not validated in tough
3/27/2025
Monitor awslabs in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.