---
title: "CVE-2026-23992\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-23992?format=md
keywords: index, follow
---

# CVE-2026-23992

Publication date 22 January 2026

Last updated 28 January 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2026-23992?format=md#impact-score)

Toggle side navigation

## Description

go-tuf is a Go implementation of The Update Framework (TUF). Starting in
version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured
TUF repository can have the configured value of signature thresholds set to
0, which effectively disables signature verification. This can lead to
unauthorized modification to TUF metadata files is possible at rest, or
during transit as no integrity checks are made. Version 2.3.1 fixes the
issue. As a workaround, always make sure that the TUF metadata roles are
configured with a threshold of at least 1.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| golang-github-theupdateframework-go-tuf | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23992)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-23992)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-23992)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-23992)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-23992>
* <https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-fphv-w9fq-2525>
* <https://github.com/theupdateframework/go-tuf/commit/b38d91fdbc69dfe31fe9230d97dafe527ea854a0>
