vciy

CVEs we hold for Sigstore

Records whose assigning authority named Sigstore as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-59891Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registrysigstore-js
CVE-2026-54787sigstore-go fails to check signature timestamps against a signing key's validity periodsigstore-go
CVE-2026-49835Sigstore Timestamp Authority: OOM due to unbounded metric label cardinalitysigstore timestamp-authority
CVE-2026-49834sigstore-go: Multi-log threshold bypass via single compromised logsigstore-go
CVE-2026-49478Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes…sigstore fulcio
CVE-2026-48816sigstore-js: Insufficient Verification of Data Authenticitysigstore-js
CVE-2026-48815sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforcedsigstore-js
CVE-2026-48791Sigstore Java has a vulnerability with bundle verification of integratedTimesigstore-java
CVE-2026-48758sigstore-js: DSSE payloadType type-binding failuresigstore-js
CVE-2026-48702Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logicsigstore rekor
CVE-2026-44310gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callerssigstore gitsign
CVE-2026-44309gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commitssigstore gitsign
CVE-2026-39984Sigstore Timestamp Authority has Improper Certificate Validation in verifiersigstore timestamp-authority
CVE-2026-39395Cosign's verify-blob-attestation reports false positive when payload parsing failssigstore cosign
CVE-2026-31830sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digestsigstore-ruby
CVE-2026-24408sigstore has CSRF possibility in OIDC authentication during signingsigstore-python
CVE-2026-24137sigstore legacy TUF client allows for arbitrary file writes with target cache path traversalsigstore
CVE-2026-24122Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be Overlookedsigstore cosign
CVE-2026-24117Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URLsigstore rekor
CVE-2026-23831Rekor COSE v0.0.1 Canonicalize crashes when passed empty Messagesigstore rekor
CVE-2026-22772Fulcio vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypasssigstore fulcio
CVE-2026-22703Cosign verification accepts any valid Rekor entry under certain conditionssigstore cosign
CVE-2025-66564Sigstore Timestamp Authority allocates excessive memory during request parsingsigstore timestamp-authority
CVE-2025-66506Fulcio allocates excessive memory during token parsingsigstore fulcio
CVE-2024-55655sigstore-python has insufficient validation of integration timestamp during verificationsigstore-python
CVE-2024-54140sigstore-java has a vulnerability with bundle verificationsigstore-java
CVE-2024-53267Vulnerability with bundle verification in sigstore-javasigstore-java
CVE-2024-51746Use of incorrect Rekor entries during verification in gitsignsigstore gitsign
CVE-2024-45395Unbounded loop over untrusted input can lead to endless data attacksigstore-go
CVE-2024-29903Cosign vulnerable to machine-wide denial of service via malicious artifactssigstore cosign
CVE-2024-29902Cosign vulnerable to system-wide denial of service via malicious attachmentssigstore cosign
CVE-2023-47122Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.sigstore gitsign
CVE-2023-46737Possible endless data attack from attacker-controlled registry in cosignsigstore cosign
CVE-2023-33199malformed proposed intoto v0.0.2 entries can cause a panic in Rekorsigstore rekor
CVE-2023-30551Rekor's compressed archives can result in OOM conditionssigstore rekor
CVE-2022-36056Vulnerabilities with blob verification in sigstore cosignsigstore cosign
CVE-2022-35930Ability to bypass attestation verification in sigstore PolicyControllersigstore policy-controller
CVE-2022-35929False positive signature verification in cosignsigstore cosign
CVE-2022-23649Improper Certificate Validation in Cosignsigstore cosign

39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.