CVE-2026-54787

EUVD-2026-51665
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 0.51%
Debian logo
Debian Releases
Debian Product
Codename
sigstore-go
forky
1.3.0-1
fixed
sid
1.3.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sigstore-go
jammy
dne
noble
dne
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
gh
Azure Linux 3.0
0:2.97.0-1.azl3
fixed