📦 Tough

by Amazon

🔍 What is Tough?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-41150

HIGH CVSS 8.2 Oct 19, 2021

CVE-2021-41150 is a path traversal vulnerability in the Tough TUF library that allows attackers to overwrite arbitrary JSON files on the system when repositories are cached or loaded. This affects sys...

CVE-2021-41149

HIGH CVSS 8.2 Oct 19, 2021

CVE-2021-41149 is a path traversal vulnerability in the Tough TUF library that allows attackers to overwrite arbitrary files on the system when caching repositories or saving targets. This affects all...

CVE-2025-2885

MEDIUM CVSS 4.5 Mar 27, 2025

This vulnerability in the tough library allows attackers to supply arbitrary version numbers in root metadata files, potentially causing clients to fetch unintended versions of software packages. It a...

CVE-2025-2887

MEDIUM CVSS 4.5 Mar 27, 2025

This vulnerability in the tough library allows clients to fetch target files from incorrect sources during delegated target rollbacks, potentially leading to altered file contents. It affects systems ...