CVE-2026-6966: Signature Threshold Bypass in awslabs/tough Delegated Roles

Published Apr 24, 2026
·
Updated

Summary Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role metadata.

Impact The tough library, prior to 0.22.0, does not properly verify the uniqueness of keys in the signatures provided to meet the threshold of cryptographic signatures in delegated targets. It allows actors with access to a valid signing key to create multiple valid signatures in order to circumvent TUF requiring a minimum threshold of unique keys before the metadata is considered valid.

Patches This issue has been addressed in tough version 0.22.0 and tuftool version 0.15.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds No workarounds to this issue are known.

References CVE-2026-6966

If there are any questions or comments about this advisory, please contact [AWS/Amazon] Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.

Acknowledgement

Amazon Web Services Labs would like to thank Emily Albini of Oxide Computer and Oleh Konko of 1seal for collaborating on this issue through the coordinated vulnerability disclosure process

Other sources

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role metadata.

We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.

MITRE

Affected Software

6 affected componentsFixes available
awslabs tough<0.22.0
awslabs tuftool<0.15.0
rust/tuftool<0.15.0
0.15.0
rust/tough<0.22.0
0.22.0
Amazon Tough Rust<0.22.0
Amazon Tuftool Rust<0.15.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/tuftool to a version that resolves this vulnerability.

    Fixed in 0.15.0
  2. Upgrade

    Upgrade rust/tough to a version that resolves this vulnerability.

    Fixed in 0.22.0
  3. Upgrade

    Upgrade awslabs/tough to a version that resolves this vulnerability.

    Fixed in 0.22.0
  4. Upgrade

    Upgrade tuftool to a version that resolves this vulnerability.

    Fixed in 0.15.0

Event History

Apr 24, 2026
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
May 5, 2026
Advisory Published
via GitHub·06:46 PM
Data Sourced
via GitHub·06:46 PM
DescriptionSeverityWeaknessAffected Software
Sep 20, 58317
Event
via FIRST·07:53 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6966?

CVE-2026-6966 has been classified as a critical vulnerability due to its potential to bypass signature threshold requirements.

2

How do I fix CVE-2026-6966?

To mitigate CVE-2026-6966, upgrade awslabs/tough to version 0.22.0 or higher and awslabs/tuftool to version 0.15.0 or higher.

3

Who is affected by CVE-2026-6966?

CVE-2026-6966 affects users of awslabs/tough versions prior to 0.22.0 and awslabs/tuftool versions prior to 0.15.0.

4

What type of attack does CVE-2026-6966 enable?

CVE-2026-6966 allows remote authenticated users to bypass TUF signature threshold requirements by duplicating existing valid signatures.

5

When was CVE-2026-6966 disclosed?

CVE-2026-6966 was disclosed on 2026-01-19.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203