CVE-2026-48815Medium· 5.9▾ SunlitA flaw was found in sigstore. The `certificateOIDs` option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
Last analysed / modified upstream
5.9 → 7.5
medium → high
7.5 → 5.9
high → medium
5.9 → 7.5
medium → high
7.5 → 5.9
high → medium
5.9 → 7.5
medium → high
7.5 → 5.9
high → medium
A flaw was found in sigstore. The certificateOIDs option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This allows unauthorized certificates to be accepted, bypassing security policies that rely on specific certificate extension object identifiers (OIDs). As a result, applications that depend on this option for security receive no protection, potentially leading to the acceptance of malicious or untrusted artifacts.
sigstore: Sigstore: Unauthorized certificates accepted due to ignored certificateOIDs verification option — rated Moderate by Red Hat. Released 2026-07-01, updated 2026-09-10.
Affected:
No fix planned:
Not affected:
Will not fix
Workarounds / mitigations:
The majority of products have sigstore-js as a transitive dependency from the npm v10.9.7 package.
sh-5.1$ npm ls sigstore
[email protected] /usr/lib/node_modules/npm
+-- @npmcli/[email protected]
| `-- @npmcli/[email protected]
| `-- [email protected]
| `-- [email protected] deduped
+-- [email protected]
| `-- [email protected]
`-- [email protected]
`-- [email protected] deduped
Affected packages:
sigstore <= 4.1.0Patched in:
sigstore 4.1.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49834Medium· 5.9github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log (CVE-2026-49834)
CVE-2026-19693High· 8.1extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)
CVE-2026-73088High· 7.5Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools
CVE-2026-73089High· 7.5Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools
CVE-2026-59879Medium· 5.3immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)
CVE-2026-59871Medium· 5.3node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)