---
id: CVE-2026-23991
title: >-
  github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed
  server response (CVE-2026-23991)
summary: >-
  A denial of service flaw has been discovered in go-tuf. If the TUF repository
  (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not
  well formed TUF metadata), the client will panic during parsing, causing a
  denial o…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-754
vendor: Red Hat
product: OpenShift Pipelines
affected:
  - openshift_pipelines
  - advanced_cluster_security 4
  - openshift_dev_spaces
  - trusted_artifact_signer
  - web_terminal
  - security_profiles_operator
  - zero_trust_workload_identity_manager
  - zero_trust_workload_identity_manager_tech_preview
patched:
  - github.com/theupdateframework/go-tuf/v2 2.3.1
published: '2026-01-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T04:22:53+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23991.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23991.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-23991'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2431928'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-23991'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23991'
  - url: >-
      https://github.com/theupdateframework/go-tuf/commit/73345ab6b0eb7e59d525dac17a428f043074cef6
  - url: 'https://github.com/theupdateframework/go-tuf/releases/tag/v2.3.1'
  - url: >-
      https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-846p-jg2w-w324
  - url: 'https://github.com/theupdateframework/go-tuf'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.0059
epssPercentile: 0.45917
aliases:
  - GHSA-846p-jg2w-w324
  - GO-2026-4348
ecosystem: go
ingestedAt: '2026-08-07T19:14:16.253Z'
---

## Overview

A denial of service flaw has been discovered in go-tuf. If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: OpenShift Pipelines, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Dev Spaces, Red Hat Trusted Artifact Signer, Red Hat Web Terminal, Security Profiles Operator, … · no fix planned: OpenShift Pipelines, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Dev Spaces, Red Hat Trusted Artifact Signer, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23991.json)

**github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed server response** — rated Moderate by Red Hat. Released 2026-01-22, updated 2026-09-23.

Affected:

- OpenShift Pipelines
- Red Hat Advanced Cluster Security 4
- Red Hat OpenShift Dev Spaces
- Red Hat Trusted Artifact Signer
- Red Hat Web Terminal
- Security Profiles Operator
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview

No fix planned:

- OpenShift Pipelines
- Red Hat Advanced Cluster Security 4
- Red Hat OpenShift Dev Spaces
- Red Hat Trusted Artifact Signer
- Red Hat Web Terminal
- Security Profiles Operator
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview

## Remediation

Fix deferred

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2026-23991)

Affected packages:

- `github.com/theupdateframework/go-tuf/v2 < 2.3.1`

Patched in:

- `github.com/theupdateframework/go-tuf/v2 2.3.1`

Source: https://osv.dev/vulnerability/GHSA-846p-jg2w-w324
