{"id":"CVE-2026-23831","title":"github.com/sigstore/rekor: Rekor denial of service (CVE-2026-23831)","summary":"Rekor’s cose v0.0.1 entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec.message. validate() returns nil (success) when message is empty, leaving sign1Msg uninitialized, and Ca…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":"CWE-476","vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.22","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","compliance_operator","confidential_compute_attestation","file_integrity_operator","kernel_module_management_operator_for_red_hat_openshift","logging_subsystem_for_red_hat_openshift","logical_volume_manager_storage","migration_toolkit_for_containers","migration_toolkit_for_virtualization","multiarch_tuning_operator","multicluster_engine_for_kubernetes","network_observability_operator","node_healthcheck_operator","openshift_api_for_data_protection","openshift_developer_tools_and_services","openshift_lightspeed","openshift_pipelines","openshift_serverless","openshift_service_mesh 2","openshift_service_mesh 3","power_monitoring_for_red_hat_openshift","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","ansible_automation_platform 2","build_of_kueue","certification_program_for_red_hat_enterprise_linux 9","enterprise_linux 10","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openshift_container_platform 4","openshift_dev_spaces","openshift_gitops","openstack_platform 18.0","quay 3","trusted_artifact_signer","web_terminal","security_profiles_operator","zero_trust_workload_identity_manager","zero_trust_workload_identity_manager_tech_preview"],"patched":["openshift_data_foundation 4.22"],"published":"2026-01-22","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:21:30+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23831.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23831.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-23831"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2432169"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-23831"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23831"},{"url":"https://github.com/sigstore/rekor/commit/39bae3d192bce48ef4ef2cbd1788fb5770fee8cd"},{"url":"https://github.com/sigstore/rekor/releases/tag/v1.5.0"},{"url":"https://github.com/sigstore/rekor/security/advisories/GHSA-273p-m2cw-6833"},{"url":"https://access.redhat.com/errata/RHSA-2026:37387"},{"url":"https://github.com/sigstore/rekor"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00436,"epssPercentile":0.35192,"aliases":["GHSA-273p-m2cw-6833","GO-2026-4354"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.744Z","slug":"CVE-2026-23831","body":"## Overview\n\nRekor’s cose v0.0.1 entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec.message. validate() returns nil (success) when message is empty, leaving sign1Msg uninitialized, and Canonicalize() later dereferences v.sign1Msg.Payload. A malformed proposed entry of the cose/v0.0.1 type can cause a panic on a thread within the Rekor process. The thread is recovered so the client receives a 500 error message and service still continues, so the availability impact of this is minimal.\n\n## Vendor advisories\n\n- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Compliance Operator, Confidential Compute Attestation, File Integrity Operator, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Compliance Operator, Confidential Compute Attestation, File Integrity Operator, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23831.json)\n\n**github.com/sigstore/rekor: Rekor denial of service** — rated Moderate by Red Hat. Released 2026-01-22, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Compliance Operator\n- Confidential Compute Attestation\n- File Integrity Operator\n- Kernel Module Management Operator for Red Hat Openshift\n- Logging Subsystem for Red Hat OpenShift\n- Logical Volume Manager Storage\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Kueue\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat OpenShift GitOps\n- Red Hat OpenStack Platform 18.0\n- Red Hat Quay 3\n- Red Hat Trusted Artifact Signer\n- Red Hat Web Terminal\n- Security Profiles Operator\n- Zero Trust Workload Identity Manager\n- Zero Trust Workload Identity Manager - Tech Preview\n\nFixed:\n\n- Red Hat Openshift Data Foundation 4.22\n\nNo fix planned:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Compliance Operator\n- Confidential Compute Attestation\n- File Integrity Operator\n- Kernel Module Management Operator for Red Hat Openshift\n- Logging Subsystem for Red Hat OpenShift\n- Logical Volume Manager Storage\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Kueue\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat OpenShift GitOps\n- Red Hat OpenStack Platform 18.0\n- Red Hat Quay 3\n- Red Hat Trusted Artifact Signer\n- Red Hat Web Terminal\n- Security Profiles Operator\n- Zero Trust Workload Identity Manager\n- Zero Trust Workload Identity Manager - Tech Preview\n\nNot affected:\n\n- Red Hat Openshift Data Foundation 4.22\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf https://access.redhat.com/errata/RHSA-2026:37387\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-23831)\n\nAffected packages:\n\n- `github.com/sigstore/rekor < 1.5.0`\n\nPatched in:\n\n- `github.com/sigstore/rekor 1.5.0`\n\nSource: https://osv.dev/vulnerability/GHSA-273p-m2cw-6833","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}