VYPR

Sigstore

by Sigstore

gem: sigstore

Source repositories

CVEs (7)

  • CVE-2026-59891CriJul 14, 2026
    risk 0.55cvss 9.6epss 0.00

    sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because…

  • CVE-2026-31830HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.00

    sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verify does not propagate the VerificationFailure returned by verify_in_toto when the artifact digest does not match the digest in the…

  • CVE-2026-48816MedJul 14, 2026
    risk 0.35cvss 6.5epss 0.00

    sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not…

  • CVE-2026-48815HigJul 14, 2026
    risk 0.31cvss 7.5epss 0.00

    sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked…

  • CVE-2026-24137MedJan 23, 2026
    risk 0.31cvss 5.8epss 0.00

    sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target…

  • CVE-2026-48758MedJul 14, 2026
    risk 0.28cvss 5.4epss 0.00

    sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when converting the PAE string to bytes, allowing payloadType to be mutated after signing without…

  • CVE-2024-45395LowSep 4, 2024
    risk 0.13cvss 3.1epss 0.00

    sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier is provided a maliciously crafted Sigstore Bundle containing large amounts of verifiable data, in the form of signed…