CVE-2026-49835

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/<uuid> or random HTTP methods and create unbounded permanent time-series entries that exhaust memory. This issue is fixed in version 2.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:sigstore_timestamp_authority:*:*:*:*:*:*:*:*

History

30 Jul 2026, 14:14

Type Values Removed Values Added
CPE cpe:2.3:a:linuxfoundation:sigstore_timestamp_authority:*:*:*:*:*:*:*:*
First Time Linuxfoundation sigstore Timestamp Authority
Linuxfoundation
References () https://github.com/sigstore/timestamp-authority/commit/506ec57b6ac2ea1e4739322e47453469425b69b5 - () https://github.com/sigstore/timestamp-authority/commit/506ec57b6ac2ea1e4739322e47453469425b69b5 - Patch
References () https://github.com/sigstore/timestamp-authority/releases/tag/v2.1.0 - () https://github.com/sigstore/timestamp-authority/releases/tag/v2.1.0 - Product, Release Notes
References () https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-9c54-x2g4-v92j - () https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-9c54-x2g4-v92j - Mitigation, Vendor Advisory

17 Jul 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-17 19:17

Updated : 2026-07-30 14:14


NVD link : CVE-2026-49835

Mitre link : CVE-2026-49835

CVE.ORG link : CVE-2026-49835


JSON object : View

Products Affected

linuxfoundation

  • sigstore_timestamp_authority
CWE
CWE-770

Allocation of Resources Without Limits or Throttling