CVE-2026-23992 | theupdateframework go-tuf up to 2.3.0 signature verification (GHSA-fphv-w9fq-2525 / Nessus ID 296222)
A vulnerability was found in theupdateframework go-tuf up to 2.3.0. It has been declared as problematic. This affects an unknown part. Such manipulation leads to improper verification of cryptographic signature.
This vulnerability is listed as CVE-2026-23992. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.