github.com/sigstore/sigstore-go
Go library for Sigstore signing and verification
Activity
- Latest release
- 2d ago
- Total releases
- 23
- Cadence
- ~24 days
- Last 12 months
- 7
Reach
- Stars
- 89
Details
- First release
- Jan 24, 2024
| Version | Released | |
|---|---|---|
v1.3.0
minor
|
v1.3.0
minor
Dependencies (21)
+ 13 more |
|
v1.2.2
patch
|
v1.2.2
patch
Dependencies (21)
+ 13 more |
|
v1.2.1
patch
|
v1.2.1
patch
Dependencies (21)
+ 13 more |
|
v1.2.0
minor
1 CVE
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (21)
+ 13 more |
|
v1.1.4
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (19)
+ 11 more |
|
v1.1.3
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (19)
+ 11 more |
|
v1.1.2
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (19)
+ 11 more |
|
v1.1.1
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (19)
+ 11 more |
|
v1.1.0
minor
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (19)
+ 11 more |
|
v1.0.0
major
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (18)
+ 10 more |
|
v0.7.3
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v0.7.3
patch
Dependencies (18)
+ 10 more |
|
v0.7.2
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v0.7.2
patch
Dependencies (18)
+ 10 more |
|
v0.7.1
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v0.7.1
patch
Dependencies (18)
+ 10 more |
|
v0.7.0
minor
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (18)
+ 10 more |
|
v0.6.2
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v0.6.2
patch
Dependencies (18)
+ 10 more |
|
v0.6.1
patch
2 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev |
v0.6.1
patch
Dependencies (17)
+ 9 more |
|
v0.6.0
minor
3 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-45395
GO-2024-3116
GHSA-cq38-jh5f-37mq
Sep 06, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go Fixed in
0.6.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (17)
+ 9 more |
|
v0.5.1
patch
3 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-45395
GO-2024-3116
GHSA-cq38-jh5f-37mq
Sep 06, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go Fixed in
0.6.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.1
patch
Dependencies (17)
+ 9 more |
|
v0.5.0
minor
3 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-45395
GO-2024-3116
GHSA-cq38-jh5f-37mq
Sep 06, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go Fixed in
0.6.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (17)
+ 9 more |
|
v0.4.0
minor
3 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-45395
GO-2024-3116
GHSA-cq38-jh5f-37mq
Sep 06, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go Fixed in
0.6.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (17)
+ 9 more |
|
v0.3.0
minor
3 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-45395
GO-2024-3116
GHSA-cq38-jh5f-37mq
Sep 06, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go Fixed in
0.6.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (17)
+ 9 more |
|
v0.2.0
minor
3 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-45395
GO-2024-3116
GHSA-cq38-jh5f-37mq
Sep 06, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go Fixed in
0.6.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (17)
+ 9 more |
|
v0.1.0
initial
3 CVEs
CVE-2026-54787
GHSA-wqqc-jjcq-vfxm
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
sigstore-go fails to check signature timestamps against a signing key's validity period for self-managed long-lived keys without certificates. ImpactTo verify a bundle with a self-managed long-lived key, the key needs to be wrapped in an
Despite the API contract, the validator does not check the bundle signing time against the validity window. Attackers that obtain expired key materials may be able to sign bundles with those materials that are accepted despite a configured expiry date. This issue only impacts the long-lived signing key workflow, and not standard deployments involving a certificate authority. Reproduction stepsStart from a sigstore-go checkout:
Apply the patch containing the test case and associated materials:
Run the test:
On vulnerable code, the test fails because verification succeeds even though the trusted
Fixed in
1.2.1
References
Updated Jul 31, 2026 · Source: OSV.dev
CVE-2026-49834
GO-2026-5952
GHSA-9vcr-p3rj-q5q6
Jul 17, 2026
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go Fixed in
1.2.0
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2024-45395
GO-2024-3116
GHSA-cq38-jh5f-37mq
Sep 06, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go Fixed in
0.6.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (16)
+ 8 more |