PT-2026-54439 · Maven+3 · Dev.Sigstore:Sigstore-Java+2

CVE-2026-48791

·

Published

2026-06-30

·

Updated

2026-08-13

CVSS v3.1

2.0

Low

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions sigstore-java version 2.0.0
Description A regression occurred where the verification of the integrated time (Rekor entry time) against the Fulcio certificate was erroneously removed. This allows a malicious actor who has exfiltrated a temporary private key used during signing to reuse an old Fulcio certificate without needing direct access to the user's credentials. The issue was caused by an incorrect implementation in the sigstore-conformance test and a specific code removal.
Recommendations Update sigstore-java to version 2.1.0. Audit transparency logs for unauthorized signatures for any suspected reused identity. Re-verify artifacts using the latest version of sigstore-java or another current sigstore client.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48791
GHSA-QQW8-7C2R-JXCH

Affected Products

Dev.Sigstore:Sigstore-Java
Golang-Github-Sigstore-Sigstore
Sigstore-Java