bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE

show all
Thursday, August 20, 2026

Critical Security Issues Found in tough Library and tuftool CLI

AWS flagged multiple vulnerabilities (CVE-2026-6966, CVE-2026-6967, CVE-2026-6968) in tough, a Rust library for TUF repository management, and its tuftool CLI. Affected versions: tough 0.1.0–0.21.x and tuftool 0.1.0–0.14.x. If you're using these tools for signing or managing update repositories, you need to patch immediately. Check AWS Security Bulletin 2026-019-AWS for details and fixes.

source: [aws/security-bulletin]