CVE-2026-49834Medium· 5.9▾ SunlitA flaw was found in sigstore-go, a Go library for Sigstore signing and verification. This vulnerability allows a single compromised transparency log or Certificate Transparency (CT) log to bypass the multi-log threshold requirements. An at…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
Last analysed / modified upstream
A flaw was found in sigstore-go, a Go library for Sigstore signing and verification. This vulnerability allows a single compromised transparency log or Certificate Transparency (CT) log to bypass the multi-log threshold requirements. An attacker could exploit this by compromising a single log, thereby defeating the intended security policy and potentially compromising the integrity of the verification process.
github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log — rated Moderate by Red Hat. Released 2026-07-17, updated 2026-09-10.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:47889 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:44162 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:47891
Affected packages:
github.com/sigstore/sigstore-go <= 1.1.4Patched in:
github.com/sigstore/sigstore-go 1.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48815Medium· 5.9sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)
CVE-2026-73500High· 7.5etcd is a distributed key-value store for the data of a distributed system
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror
CVE-2026-94368High· 7.1A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway
CVE-2026-71576High· 8.5A flaw was found in multicluster-global-hub
CVE-2026-42784High· 7.4A flaw was found in sequoia-openpgp