CVE Tools

Sigstore

13 CVEs tracked since 2026. Since Jan 2026, none of them reached CISA KEV.

Sigstore CVEs per month

Jan 2026 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Sigstore CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0160
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-0770

Products

The products that kept showing up in Sigstore's monthly top three, with their CVEs summed over those months.

  1. Sigstore-js41 month
  2. Rekor21 month
  3. Sigstore-go21 month
  4. Cosign11 month
  5. Sigstore-python11 month
  6. Timestamp-authority11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Sigstore.

  1. CVE-2026-48702Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic7.5
  2. CVE-2026-49478Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage8.7
  3. CVE-2026-48791Sigstore Java has a vulnerability with bundle verification of integratedTime2.0
  4. CVE-2026-54787sigstore-go fails to check signature timestamps against a signing key's validity period3.1
  5. CVE-2026-49834sigstore-go: Multi-log threshold bypass via single compromised log5.9
  6. CVE-2026-49835Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality5.9
  7. CVE-2026-48816sigstore-js: Insufficient Verification of Data Authenticity6.5
  8. CVE-2026-48758sigstore-js: DSSE payloadType type-binding failure5.4
  9. CVE-2026-48815sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced7.5
  10. CVE-2026-59891Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry9.6
  11. CVE-2026-44309gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits5.3
  12. CVE-2026-44310gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers5.4
  13. CVE-2026-39984Sigstore Timestamp Authority has Improper Certificate Validation in verifier5.5
  14. CVE-2026-39395Cosign's verify-blob-attestation reports false positive when payload parsing fails4.3
  15. CVE-2026-31830sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest7.5

The record

Peak rank
#162 in Jan 2026
Busiest month shown
Jul 2026, 7 CVEs
Months with a KEV entry
0 since Jan 2026
Monthly snapshots
2 since 2026
Sigstore's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store