CVEs we hold for Sigstore
Records whose assigning authority named Sigstore as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-59891Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registrysigstore-js
CVE-2026-54787sigstore-go fails to check signature timestamps against a signing key's validity periodsigstore-go
CVE-2026-49835Sigstore Timestamp Authority: OOM due to unbounded metric label cardinalitysigstore timestamp-authority
CVE-2026-49478Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes…sigstore fulcio
CVE-2026-48815sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforcedsigstore-js
CVE-2026-48791Sigstore Java has a vulnerability with bundle verification of integratedTimesigstore-java
CVE-2026-48702Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logicsigstore rekor
CVE-2026-44310gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callerssigstore gitsign
CVE-2026-44309gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commitssigstore gitsign
CVE-2026-39984Sigstore Timestamp Authority has Improper Certificate Validation in verifiersigstore timestamp-authority
CVE-2026-39395Cosign's verify-blob-attestation reports false positive when payload parsing failssigstore cosign
CVE-2026-31830sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digestsigstore-ruby
CVE-2026-24137sigstore legacy TUF client allows for arbitrary file writes with target cache path traversalsigstore
CVE-2026-24122Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be Overlookedsigstore cosign
CVE-2026-24117Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URLsigstore rekor
CVE-2026-22772Fulcio vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypasssigstore fulcio
CVE-2026-22703Cosign verification accepts any valid Rekor entry under certain conditionssigstore cosign
CVE-2025-66564Sigstore Timestamp Authority allocates excessive memory during request parsingsigstore timestamp-authority
CVE-2024-55655sigstore-python has insufficient validation of integration timestamp during verificationsigstore-python
CVE-2024-29903Cosign vulnerable to machine-wide denial of service via malicious artifactssigstore cosign
CVE-2024-29902Cosign vulnerable to system-wide denial of service via malicious attachmentssigstore cosign
CVE-2023-47122Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.sigstore gitsign
CVE-2023-46737Possible endless data attack from attacker-controlled registry in cosignsigstore cosign
CVE-2022-35930Ability to bypass attestation verification in sigstore PolicyControllersigstore policy-controller
39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.