{"id":"CVE-2020-6173","aliases":["GHSA-2828-9vh6-9m6j","PYSEC-2020-146"],"url":"https://o3.security/vulnerability/CVE-2020-6173","summary":"Client Denial of Service on TUF","details":"TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.","published":"2020-01-14T19:15:13.797Z","modified":"2026-08-27T08:15:00.587662Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":{"score":0.01758,"percentile":0.75923,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"tuf","fixedVersion":"0.12.2"}],"fix":null,"references":[{"type":"FIX","url":"https://github.com/theupdateframework/tuf/commits/develop"},{"type":"FIX","url":"https://github.com/theupdateframework/tuf/issues/973"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:15:00.587662Z"}}