CVE-2026-54787

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 23:17

Updated : 2026-09-10 20:30


NVD link : CVE-2026-54787

Mitre link : CVE-2026-54787

CVE.ORG link : CVE-2026-54787


JSON object : View

Products Affected

No product.

CWE
CWE-324

Use of a Key Past its Expiration Date