FlawAtlas
Search the atlas
CVE-2026-23991 Moderate

Client DoS via malformed server response in github.com/theupdateframework/go-tuf

Client DoS via malformed server response in github.com/theupdateframework/go-tuf

Exploit probability 0.5%
Published February 2, 2026
Required by Not available
Last source change August 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/theupdateframework/go-tuf/v2
Go github.com/theupdateframework/go-tuf/v2
Unknown Unknown

7 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-23991

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.

View original source
Open Source Vulnerabilities GO-2026-4348

Client DoS via malformed server response in github.com/theupdateframework/go-tuf

View original source
Open Source Vulnerabilities GHSA-846p-jg2w-w324

# Security Disclosure: Client DoS via malformed server response ## Summary If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic _during parsing_, causing a DoS. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. ## Impact Client crashes upon receiving and parsing malformed TUF metadata. This can cause long running services to enter an restart/crash loop. ## Workarounds None currently. ## Affected code The `metadata.checkType` function did not properly type assert the (untrusted) input causing it to panic on malformed data.

View original source

05 / REFERENCES

Further evidence