sigstore
Security Productsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting sigstore.
- CVE-2026-48702Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic7.5
- CVE-2026-49478Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage8.7
- CVE-2026-48791Sigstore Java has a vulnerability with bundle verification of integratedTime2.0
- CVE-2026-54787sigstore-go fails to check signature timestamps against a signing key's validity period3.1
- CVE-2026-49834sigstore-go: Multi-log threshold bypass via single compromised log5.9
- CVE-2026-49835Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality5.9
- CVE-2026-48816sigstore-js: Insufficient Verification of Data Authenticity6.5
- CVE-2026-48758sigstore-js: DSSE payloadType type-binding failure5.4
- CVE-2026-48815sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced7.5
- CVE-2026-59891Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry9.6
- CVE-2026-44309gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits5.3
- CVE-2026-44310gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers5.4
- CVE-2026-39984Sigstore Timestamp Authority has Improper Certificate Validation in verifier5.5
- CVE-2026-39395Cosign's verify-blob-attestation reports false positive when payload parsing fails4.3
- CVE-2026-31830sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest7.5