sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wqqc-jjcq-vfxm | sigstore-go fails to check signature timestamps against a signing key's validity period |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 01 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sigstore
Sigstore sigstore-go |
|
| Vendors & Products |
Sigstore
Sigstore sigstore-go |
Fri, 31 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1. | |
| Title | sigstore-go fails to check signature timestamps against a signing key's validity period | |
| Weaknesses | CWE-324 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-31T23:36:13.441Z
Reserved: 2026-06-15T23:23:57.714Z
Link: CVE-2026-54787
Updated: 2026-07-31T23:36:08.101Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T23:30:17Z
Weaknesses
Github GHSA