Vulnerability in Sigstore Signing Library Allows Expired Key Use
CVE-2026-54787
3.1LOW
What is CVE-2026-54787?
The sigstore-go library, used for signing and verifying artifacts, contains a flaw where it fails to validate the signing timestamp of a bundle against the expiration of an associated key. This oversight permits an attacker with expired key material to sign and produce valid bundles that the system may accept. To mitigate the risk posed by this vulnerability, users should update to version 1.2.1 or later, which corrects the timestamp verification process.
Affected Version(s)
sigstore-go < 1.2.1
