Vulnerability in sigstore-java Affects Artifact Verification Process
CVE-2026-48791

2LOW

Key Information:

Vendor

Sigstore

Vendor
CVE Published:
12 August 2026

What is CVE-2026-48791?

The sigstore-java client, used for interacting with Sigstore infrastructure, has a vulnerability affecting version 2.0.0 that erroneously omitted the verification of the entry time against the Fulcio certificate. This flaw allows potential exploitation by malicious actors who gain access to a user's system and the temporary private key utilized during signing. They could then reuse an old Fulcio certificate without needing direct access to the user’s credentials. Users are urged to upgrade to version 2.1.0, which restores this critical verification and adheres to the appropriate Sigstore verification specifications. Users should also consider auditing transparency logs for any unauthorized signatures as a precautionary measure.

Affected Version(s)

sigstore-java = 2.0.0

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.