Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48815

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.

EPSS

Процентиль: 4%
0.00143
Низкий

7.5 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.9
redhat
около 1 месяца назад

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.

CVSS3: 7.5
github
около 1 месяца назад

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

EPSS

Процентиль: 4%
0.00143
Низкий

7.5 High

CVSS3

Дефекты

CWE-347