VYPR

Sigstore Go

by Sigstore

Source repositories

CVEs (3)

  • CVE-2026-49834MedJul 17, 2026
    risk 0.31cvss 5.9epss 0.00

    sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a…

  • CVE-2026-54787LowJul 31, 2026
    risk 0.13cvss 3.1epss 0.00

    sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an…

  • CVE-2024-45395LowSep 4, 2024
    risk 0.13cvss 3.1epss 0.00

    sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier is provided a maliciously crafted Sigstore Bundle containing large amounts of verifiable data, in the form of signed…