Sigstore
13 CVEs tracked since 2026. Since Jan 2026, none of them reached CISA KEV.
Sigstore CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-01 | 6 | 0 |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | null or fewer | |
| 2026-06 | null or fewer | |
| 2026-07 | 7 | 0 |
Products
The products that kept showing up in Sigstore's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Sigstore.
- CVE-2026-48702Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic7.5
- CVE-2026-49478Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage8.7
- CVE-2026-48791Sigstore Java has a vulnerability with bundle verification of integratedTime2.0
- CVE-2026-54787sigstore-go fails to check signature timestamps against a signing key's validity period3.1
- CVE-2026-49834sigstore-go: Multi-log threshold bypass via single compromised log5.9
- CVE-2026-49835Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality5.9
- CVE-2026-48816sigstore-js: Insufficient Verification of Data Authenticity6.5
- CVE-2026-48758sigstore-js: DSSE payloadType type-binding failure5.4
- CVE-2026-48815sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced7.5
- CVE-2026-59891Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry9.6
- CVE-2026-44309gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits5.3
- CVE-2026-44310gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers5.4
- CVE-2026-39984Sigstore Timestamp Authority has Improper Certificate Validation in verifier5.5
- CVE-2026-39395Cosign's verify-blob-attestation reports false positive when payload parsing fails4.3
- CVE-2026-31830sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest7.5
The record
- Peak rank
- #162 in Jan 2026
- Busiest month shown
- Jul 2026, 7 CVEs
- Months with a KEV entry
- 0 since Jan 2026
- Monthly snapshots
- 2 since 2026