tuf vulnerabilities
CVEs whose affected-version data names the tuf package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
GHSA-qp9x-wp8f-qgjjMedium· 4.0tuf has platform-dependent delegation path matching
tuf has platform-dependent delegation path matching
▾ Sunlittuf · tufvia OSV
CVE-2021-41131High· 7.5Client metadata path-traversal
Client metadata path-traversal
▾ Twilighttuf · tufEPSS 1.5%via OSV
CVE-2020-15163High· 8.7Invalid root may become trusted root in The Update Framework (TUF)
Invalid root may become trusted root in The Update Framework (TUF)
▾ Twilighttuf · tufEPSS 0.67%via OSV