Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2026-39984

4 месяца назад

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert uses the first non-CA certificate from the PKCS#7 certificate bag instead of the leaf certificate from the verified chain. An attacker can exploit this by prepending a forged certificate to the certificate bag while the message is signed with an authorized key, causing the library to validate the signature against one certificate but perform authorization checks against another. This vulnerability only affects users of the timestamp-authority/v2/pkg/verification package and does not affect the timestamp-authority service itself or sigstore-go. The issue has been fixed in version 2.0.6.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-39984

4 месяца назад

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert uses the first non-CA certificate from the PKCS#7 certificate bag instead of the leaf certificate from the verified chain. An attacker can exploit this by prepending a forged certificate to the certificate bag while the message is signed with an authorized key, causing the library to validate the signature against one certificate but perform authorization checks against another. This vulnerability only affects users of the timestamp-authority/v2/pkg/verification package and does not affect the timestamp-authority service itself or sigstore-go. The issue has been fixed in version 2.0.6.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-39984

4 месяца назад

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert uses the first non-CA certificate from the PKCS#7 certificate bag instead of the leaf certificate from the verified chain. An attacker can exploit this by prepending a forged certificate to the certificate bag while the message is signed with an authorized key, causing the library to validate the signature against one certificate but perform authorization checks against another. This vulnerability only affects users of the timestamp-authority/v2/pkg/verification package and does not affect the timestamp-authority service itself or sigstore-go. The issue has been fixed in version 2.0.6.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2026-39984

4 месяца назад

Sigstore Timestamp Authority is a service for issuing RFC 3161 timesta ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm5m-wgh2-rrg3

4 месяца назад

Sigstore Timestamp Authority has Improper Certificate Validation in verifier

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20711-1

3 месяца назад

Security update for hauler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21060-1

около 2 месяцев назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2692-1

около 1 месяца назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20702-1

3 месяца назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20809-1

3 месяца назад

Security update for trivy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-39984

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert uses the first non-CA certificate from the PKCS#7 certificate bag instead of the leaf certificate from the verified chain. An attacker can exploit this by prepending a forged certificate to the certificate bag while the message is signed with an authorized key, causing the library to validate the signature against one certificate but perform authorization checks against another. This vulnerability only affects users of the timestamp-authority/v2/pkg/verification package and does not affect the timestamp-authority service itself or sigstore-go. The issue has been fixed in version 2.0.6.

CVSS3: 5.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-39984

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert uses the first non-CA certificate from the PKCS#7 certificate bag instead of the leaf certificate from the verified chain. An attacker can exploit this by prepending a forged certificate to the certificate bag while the message is signed with an authorized key, causing the library to validate the signature against one certificate but perform authorization checks against another. This vulnerability only affects users of the timestamp-authority/v2/pkg/verification package and does not affect the timestamp-authority service itself or sigstore-go. The issue has been fixed in version 2.0.6.

CVSS3: 5.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-39984

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert uses the first non-CA certificate from the PKCS#7 certificate bag instead of the leaf certificate from the verified chain. An attacker can exploit this by prepending a forged certificate to the certificate bag while the message is signed with an authorized key, causing the library to validate the signature against one certificate but perform authorization checks against another. This vulnerability only affects users of the timestamp-authority/v2/pkg/verification package and does not affect the timestamp-authority service itself or sigstore-go. The issue has been fixed in version 2.0.6.

CVSS3: 5.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-39984

Sigstore Timestamp Authority is a service for issuing RFC 3161 timesta ...

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xm5m-wgh2-rrg3

Sigstore Timestamp Authority has Improper Certificate Validation in verifier

CVSS3: 5.5
0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20711-1

Security update for hauler

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21060-1

Security update for docker

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2692-1

Security update for docker

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20702-1

Security update for trivy

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20809-1

Security update for trivy

3 месяца назад

Уязвимостей на страницу