Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-48791Low· 2.0sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verifi…
CVE-2026-54787Low· 3.1sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without…
CVE-2026-59891Critical· 9.6PoCCredential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
CVE-2026-48816Medium· 6.5sigstore-js has Insufficient Verification of Data Authenticity
CVE-2026-49835Medium· 5.9Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
CVE-2026-48758Medium· 5.4@sigstore/core has DSSE payloadType type-binding failure
CVE-2026-44309Medium· 5.3gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
CVE-2026-44310Medium· 5.4gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
CVE-2026-24408None· 0.0sigstore CSRF possibility in OIDC authentication during signing
CVE-2026-22772Medium· 5.8Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
CVE-2025-66564High· 7.5Sigstore Timestamp Authority allocates excessive memory during request parsing
CVE-2024-55655Lowsigstore has insufficient validation of integration timestamp during verification
CVE-2024-29902Medium· 4.2Cosign malicious attachments can cause system-wide denial of service
CVE-2023-30551High· 7.5Rekor's compressed archives can result in OOM conditions
CVE-2022-35930High· 7.1PolicyController before 0.2.1 may bypass attestation verification
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.