Vulnerability in Sigstore Signing Library Allows Expired Key Use
CVE-2026-54787

3.1LOW

Key Information:

Vendor

Sigstore

Vendor
CVE Published:
31 July 2026

What is CVE-2026-54787?

The sigstore-go library, used for signing and verifying artifacts, contains a flaw where it fails to validate the signing timestamp of a bundle against the expiration of an associated key. This oversight permits an attacker with expired key material to sign and produce valid bundles that the system may accept. To mitigate the risk posed by this vulnerability, users should update to version 1.2.1 or later, which corrects the timestamp verification process.

Affected Version(s)

sigstore-go < 1.2.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.