Junglewise Threat Intelligence

CVE-2026-6967: awslabs/tough is Missing Delegated Metadata Validation

CVE-2026-6967 · Severity: low · CVSS 3.1 · Published 2026-05-05

Technologies: tough (crates.io). Vendors: crates.io.

Executive brief

awslabs/tough is Missing Delegated Metadata Validation

Affected products

  • crates.io tough
  • crates.io tuftool

Related threats