Medium severity6.5NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-48816
CVE-2026-48816
Description
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@sigstore/verifynpm | >= 3.1.0, < 3.1.1 | 3.1.1 |
Affected products
3- osv-coords2 versions
< 3.248.0-r2+ 1 more
- (no CPE)range: < 3.248.0-r2
- (no CPE)range: < 3.248.0-r2
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-xgjw-pm74-86q4ghsaADVISORY
- github.com/sigstore/sigstore-js/security/advisories/GHSA-xgjw-pm74-86q4nvdWEB
- github.com/sigstore/sigstore-js/commit/f074710a91ea9260a9ac2142345634579843a3cdnvd
- github.com/sigstore/sigstore-js/pull/1659nvd
- github.com/sigstore/sigstore-js/releases/tag/%40sigstore%2Fverify%403.1.1nvd
News mentions
0No linked articles in our index yet.