PT-2026-57022 · Unknown · Sigstore-Go

CVE-2026-49834

·

Published

2026-07-09

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions sigstore-go versions prior to 1.2.0
Description A flaw exists in the verification process when configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1). The system counts verified witnesses per entry or per validation path instead of per log authority. This allows a single compromised transparency log or Certificate Transparency (CT) log to forge multiple entries or verify multiple times, satisfying multi-log threshold requirements and bypassing the intended multi-log security policy.
Recommendations Update to version 1.2.0.

Exploit

Fix

Improper Verification of Cryptographic Signature

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-LZ81863
CVE-2026-49834
GHSA-9VCR-P3RJ-Q5Q6
GO-2026-5952
OPENSUSE-SU-2026:21483-1
RHSA-2026:44162
RHSA-2026:44451
RHSA-2026:47889
RHSA-2026:47891

Affected Products

Sigstore-Go