Executive brief
Multiple security vulnerabilities have been identified in the tough library and tuftool utility, which are used to manage secure software update repositories. These tools help ensure that software updates are authentic and have not been tampered with. If exploited, these flaws could potentially allow an attacker to compromise the integrity of the update process, leading to the distribution of malicious software to end users.
Technical details
Multiple vulnerabilities (CVE-2026-6966, CVE-2026-6967, and CVE-2026-6968) exist in the tough Rust library and the tuftool CLI, which implement The Update Framework (TUF). While specific technical root causes for each CVE are not detailed in the advisory, the flaws reside in the components responsible for generating, signing, and managing TUF repositories. An attacker could potentially exploit these issues to bypass security checks inherent in the TUF specification, such as metadata verification or signature validation. Successful exploitation could allow for man-in-the-middle attacks or the serving of malicious repository content. Users are advised to upgrade to tough version 0.22.0 or later and tuftool version 0.15.0 or later.
Affected products
- AWS tough 0.1.0 - 0.21.x
- AWS tuftool 0.1.0 - 0.14.x
CVE identifiers
- CVE-2026-6966
- CVE-2026-6967
- CVE-2026-6968
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-04-24: patched