Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-49834

Опубликовано: 17 июл. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a single compromised transparency log or CT log to satisfy multi-log threshold requirements and defeat the multi-log policy. This issue is fixed in version 1.2.0.

EPSS

Процентиль: 2%
0.00113
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.9
ubuntu
21 день назад

(sigstore-go is a Go library for Sigstore signing and verification. Pri ...)

CVSS3: 5.9
debian
24 дня назад

sigstore-go is a Go library for Sigstore signing and verification. Pri ...

CVSS3: 5.9
github
около 1 месяца назад

sigstore-go has a multi-log threshold bypass via single compromised log

EPSS

Процентиль: 2%
0.00113
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-347