sigstore vulnerabilities
CVEs whose affected-version data names the sigstore package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-24408None· 0.0sigstore CSRF possibility in OIDC authentication during signing
sigstore CSRF possibility in OIDC authentication during signing
▾ Sunlitsigstore · sigstoreEPSS 0.18%via OSV
CVE-2024-55655Lowsigstore has insufficient validation of integration timestamp during verification
sigstore has insufficient validation of integration timestamp during verification
▾ Sunlitsigstore · sigstoreEPSS 0.25%via OSV