CVE-2026-49835

EUVD-2026-45245
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/<uuid> or random HTTP methods and create unbounded permanent time-series entries that exhaust memory. This issue is fixed in version 2.1.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.24%
Affected Products (NVD)
VendorProductVersion
linuxfoundationsigstore_timestamp_authority
𝑥
< 2.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-sigstore-timestamp-authority
forky
2.1.3-2
fixed
sid
2.1.3-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-sigstore-timestamp-authority
jammy
dne
noble
dne
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
runfinch-finch
Amazon Linux 2023
0:1.17.2-1.amzn2023.0.3
fixed