© 2025-2026 PySpect
First version without a known vulnerability: 7.0.0
tuf has platform-dependent delegation path matching
Fixed in: 7.0.0
tuf's Metadata API: Targets.get_delegated_role() is missing input validation
Fixed in: 3.1.1
Python-TUF vulnerable to incorrect threshold signature computation for new root metadata
Fixed in: 0.16.0
Client metadata path-traversal
Fixed in: 0.19.0, 4ad7ae48fda594b640139c3b7eae21ed5155a102
Invalid root may become trusted root in The Update Framework (TUF)
Fixed in: 0.12.0, 3d342e648fbacdf43a13d7ba8886aaaf07334af7
Client Denial of Service on TUF
Fixed in: 0.12.2
Incorrect threshold signature computation in TUF
Fixed in: 0.12.2