{"id":"CVE-2026-23991","title":"github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed server response (CVE-2026-23991)","summary":"A denial of service flaw has been discovered in go-tuf. If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial o…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-754","vendor":"Red Hat","product":"OpenShift Pipelines","affected":["openshift_pipelines","advanced_cluster_security 4","openshift_dev_spaces","trusted_artifact_signer","web_terminal","security_profiles_operator","zero_trust_workload_identity_manager","zero_trust_workload_identity_manager_tech_preview"],"patched":["github.com/theupdateframework/go-tuf/v2 2.3.1"],"published":"2026-01-22","updated":"2026-09-23","sourceUpdated":"2026-09-23T04:22:53+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23991.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23991.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-23991"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431928"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-23991"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23991"},{"url":"https://github.com/theupdateframework/go-tuf/commit/73345ab6b0eb7e59d525dac17a428f043074cef6"},{"url":"https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1"},{"url":"https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-846p-jg2w-w324"},{"url":"https://github.com/theupdateframework/go-tuf"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.0059,"epssPercentile":0.45844,"aliases":["GHSA-846p-jg2w-w324","GO-2026-4348"],"ecosystem":"go","ingestedAt":"2026-08-07T19:14:16.253Z","slug":"CVE-2026-23991","body":"## Overview\n\nA denial of service flaw has been discovered in go-tuf. If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: OpenShift Pipelines, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Dev Spaces, Red Hat Trusted Artifact Signer, Red Hat Web Terminal, Security Profiles Operator, … · no fix planned: OpenShift Pipelines, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Dev Spaces, Red Hat Trusted Artifact Signer, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23991.json)\n\n**github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed server response** — rated Moderate by Red Hat. Released 2026-01-22, updated 2026-09-23.\n\nAffected:\n\n- OpenShift Pipelines\n- Red Hat Advanced Cluster Security 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat Trusted Artifact Signer\n- Red Hat Web Terminal\n- Security Profiles Operator\n- Zero Trust Workload Identity Manager\n- Zero Trust Workload Identity Manager - Tech Preview\n\nNo fix planned:\n\n- OpenShift Pipelines\n- Red Hat Advanced Cluster Security 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat Trusted Artifact Signer\n- Red Hat Web Terminal\n- Security Profiles Operator\n- Zero Trust Workload Identity Manager\n- Zero Trust Workload Identity Manager - Tech Preview\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-23991)\n\nAffected packages:\n\n- `github.com/theupdateframework/go-tuf/v2 < 2.3.1`\n\nPatched in:\n\n- `github.com/theupdateframework/go-tuf/v2 2.3.1`\n\nSource: https://osv.dev/vulnerability/GHSA-846p-jg2w-w324","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}