Vulnerability in sigstore-java Affects Artifact Verification Process
CVE-2026-48791
What is CVE-2026-48791?
The sigstore-java client, used for interacting with Sigstore infrastructure, has a vulnerability affecting version 2.0.0 that erroneously omitted the verification of the entry time against the Fulcio certificate. This flaw allows potential exploitation by malicious actors who gain access to a user's system and the temporary private key utilized during signing. They could then reuse an old Fulcio certificate without needing direct access to the user’s credentials. Users are urged to upgrade to version 2.1.0, which restores this critical verification and adheres to the appropriate Sigstore verification specifications. Users should also consider auditing transparency logs for any unauthorized signatures as a precautionary measure.
Affected Version(s)
sigstore-java = 2.0.0
