CVE-2026-54787CWE-324

CVE-2026-54787

Low · published August 1, 2026

CVSS v3.1
3.1
EPSS
0%
Percentile
0.5
In the wild
Unconfirmed
What it is

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.

The record
Technical detail
CVSS v3.1
3.1 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00090 · 0.5th percentile
Weakness
CWE-324 · Use of a Key Past its Expiration Date
Published
2026-08-01T03:17Z
References (5)
EPSS history
Timeline
  • 31 JUL 21:58Z
    sigstore-go fails to check signature timestamps against a signing key's validity period
    cvelistv5