CVE-2026-54787
- EPSS 0.09%
- Veröffentlicht 31.07.2026 21:58:14
- Zuletzt bearbeitet 01.08.2026 00:17:17
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificat...
CVE-2026-49834
- EPSS 0.11%
- Veröffentlicht 17.07.2026 19:20:06
- Zuletzt bearbeitet 30.07.2026 13:18:22
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per ...
CVE-2024-45395
- EPSS 0.47%
- Veröffentlicht 04.09.2024 21:15:14
- Zuletzt bearbeitet 24.09.2024 16:50:07
sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier is provided a maliciously crafted Sigstore Bundle containing large amounts of verifiable data, in...