Sigstore

    Dashboard / Vendors

    Products: 11
    Vulnerabilities: 32
    Known Exploited: 0
    0
    Critical Level Threats
    6
    High Level Threats
    17
    Medium Level Threats
    8
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-48791

    Sigstore Java has a vulnerability with bundle verification of integratedTime

    Last Modified: Aug 13, 2026
    Published: Aug 12, 2026

    CVE-2026-54787

    sigstore-go fails to check signature timestamps against a signing key's validity period

    Last Modified: Aug 02, 2026
    Published: Jul 31, 2026

    CVE-2026-49834

    sigstore-go: Multi-log threshold bypass via single compromised log

    Last Modified: Jul 28, 2026
    Published: Jul 17, 2026

    CVE-2026-48815

    sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced

    Last Modified: Jul 30, 2026
    Published: Jul 01, 2026

    CVE-2026-48816

    sigstore-js: Insufficient Verification of Data Authenticity

    Last Modified: Jul 30, 2026
    Published: Jul 01, 2026
    Items Per Page