CVE-2026-6967: Missing Delegated Metadata Validation in awslabs/tough

Published Apr 24, 2026
·
Updated

Summary Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, because loaddelegations does not apply the same validation checks as the top-level targets metadata path.

Impact The tough library, prior to 0.22.0, does not properly verify delegated target metadata. It allows someone with write access to the metadata to serve expired or otherwise invalid targets from a TUF repository which tough will then trust rather than reject.

Impacted Versions: tough 0.9.0 through 0.21.x, tuftool through 0.14.x

Patches This issue has been addressed in tough version 0.22.0 and tuftool version 0.15.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds No workarounds to this issue are known.

References CVE-2026-6967 If there are any questions or comments about this advisory, please contact [AWS/Amazon] Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.

Acknowledgement

Amazon Web Services Labs would like to thank Oleh Konko of 1seal for collaborating on this issue through the coordinated vulnerability disclosure process.

Other sources

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, because loaddelegations does not apply the same validation checks as the top-level targets metadata path.

We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.

MITRE

Affected Software

6 affected componentsFixes available
awslabs tough<0.22.0
awslabs tuftool<0.15.0
rust/tuftool<0.15.0
0.15.0
rust/tough>=0.9.0<0.22.0
0.22.0
Amazon Tough Rust>=0.9.0<0.22.0
Amazon Tuftool Rust<0.15.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/tuftool to a version that resolves this vulnerability.

    Fixed in 0.15.0
  2. Upgrade

    Upgrade rust/tough to a version that resolves this vulnerability.

    Fixed in 0.22.0
  3. Upgrade

    Upgrade awslabs/tough to a version that resolves this vulnerability.

    Fixed in 0.22.0
  4. Upgrade

    Upgrade awslabs/tuftool to a version that resolves this vulnerability.

    Fixed in 0.15.0

Event History

Apr 24, 2026
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
May 5, 2026
Advisory Published
via GitHub·06:46 PM
Data Sourced
via GitHub·06:46 PM
DescriptionSeverityWeaknessAffected Software
Sep 20, 58317
Event
via FIRST·04:08 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6967?

CVE-2026-6967 is classified as a high-severity vulnerability due to its potential impact on the integrity of delegated signing authority.

2

How do I fix CVE-2026-6967?

To fix CVE-2026-6967, upgrade to tough version 0.22.0 or later and tuftool version 0.15.0 or later.

3

Who is affected by CVE-2026-6967?

CVE-2026-6967 affects users of awslabs/tough versions before 0.22.0 and awslabs/tuftool versions before 0.15.0.

4

What is the impact of CVE-2026-6967?

The impact of CVE-2026-6967 is that it allows remote authenticated users to bypass critical integrity checks, potentially compromising system security.

5

What does delegated metadata validation mean in the context of CVE-2026-6967?

Delegated metadata validation refers to the process of verifying metadata integrity in delegated signing scenarios, which is improperly handled in CVE-2026-6967.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203