Medium severity5.3NVD Advisory· Published Jan 14, 2020· Updated Jun 17, 2026
CVE-2020-6173
CVE-2020-6173
Description
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tufPyPI | >= 0.7.2, < 0.12.2 | 0.12.2 |
Affected products
3- TUF/TUFdescription
- cpe:2.3:a:linuxfoundation:the_update_framework:*:*:*:*:*:*:*:*Range: >=0.7.2,<=0.12.1
Patches
Vulnerability mechanics
References
6- github.com/theupdateframework/tuf/commits/developnvdPatchThird Party AdvisoryWEB
- github.com/theupdateframework/tuf/issues/973nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-2828-9vh6-9m6jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-6173ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/tuf/PYSEC-2020-146.yamlghsaWEB
- github.com/theupdateframework/tuf/security/advisories/GHSA-2828-9vh6-9m6jghsaWEB
News mentions
0No linked articles in our index yet.