CVE-2026-54787
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.09%
- CWE
- CWE-324
- Published
- 2026-07-31
- Last modified
- 2026-08-01
Affected products
- sigstore sigstore-go
Weakness type
Related vulnerabilities
- CVE-2026-39923 — Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
- CVE-2026-52809 — Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
- CVE-2025-33012 — IBM Db2 improper account lockout
- CVE-2025-48813 — Virtual Secure Mode Spoofing Vulnerability
- CVE-2023-5342 — Shim: expired secure boot certificate
- CVE-2025-2291 — PgBouncer default auth_query does not take Postgres password expiry into account
- CVE-2025-31123 — Zitadel Expired JWT Keys Usable for Authorization Grants
- CVE-2024-7318 — Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverity