PT-2026-54439 · Maven+3 · Dev.Sigstore:Sigstore-Java+2
CVE-2026-48791
·
Published
2026-06-30
·
Updated
2026-08-13
CVSS v3.1
2.0
Low
| Vector | AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
sigstore-java version 2.0.0
Description
A regression occurred where the verification of the integrated time (Rekor entry time) against the Fulcio certificate was erroneously removed. This allows a malicious actor who has exfiltrated a temporary private key used during signing to reuse an old Fulcio certificate without needing direct access to the user's credentials. The issue was caused by an incorrect implementation in the sigstore-conformance test and a specific code removal.
Recommendations
Update sigstore-java to version 2.1.0.
Audit transparency logs for unauthorized signatures for any suspected reused identity.
Re-verify artifacts using the latest version of sigstore-java or another current sigstore client.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dev.Sigstore:Sigstore-Java
Golang-Github-Sigstore-Sigstore
Sigstore-Java