Sigstore

Sigstore-go

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 31.07.2026 21:58:14
  • Zuletzt bearbeitet 01.08.2026 00:17:17

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificat...

  • EPSS 0.11%
  • Veröffentlicht 17.07.2026 19:20:06
  • Zuletzt bearbeitet 30.07.2026 13:18:22

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per ...

  • EPSS 0.47%
  • Veröffentlicht 04.09.2024 21:15:14
  • Zuletzt bearbeitet 24.09.2024 16:50:07

sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier is provided a maliciously crafted Sigstore Bundle containing large amounts of verifiable data, in...