Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wqqc-jjcq-vfxm | sigstore-go fails to check signature timestamps against a signing key's validity period |
Sat, 01 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sigstore
Sigstore sigstore-go |
|
| Vendors & Products |
Sigstore
Sigstore sigstore-go |
Fri, 31 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1. | |
| Title | sigstore-go fails to check signature timestamps against a signing key's validity period | |
| Weaknesses | CWE-324 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-31T23:36:13.441Z
Reserved: 2026-06-15T23:23:57.714Z
Link: CVE-2026-54787
Updated: 2026-07-31T23:36:08.101Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T23:30:17Z
-
CWE-324
Use of a Key Past its Expiration Date
Github GHSA