VYPR
Medium severity5.9NVD Advisory· Published Jul 17, 2026· Updated Jul 30, 2026

CVE-2026-49835

CVE-2026-49835

Description

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/ or random HTTP methods and create unbounded permanent time-series entries that exhaust memory. This issue is fixed in version 2.1.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/sigstore/timestamp-authority/v2Go
< 2.1.02.1.0
github.com/sigstore/timestamp-authorityGo
<= 1.2.9

Affected products

147

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.