CVE-2026-54787

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.
Configurations

No configuration.

History

01 Aug 2026, 00:17

Type Values Removed Values Added
References () https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm - () https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm -

31 Jul 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-31 23:17

Updated : 2026-08-01 00:17


NVD link : CVE-2026-54787

Mitre link : CVE-2026-54787

CVE.ORG link : CVE-2026-54787


JSON object : View

Products Affected

No product.

CWE
CWE-324

Use of a Key Past its Expiration Date