Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

redhat логотип

CVE-2026-48815

3 месяца назад

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-48815

2 месяца назад

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52v5-jr5w-gjxr

3 месяца назад

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-48815

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.

CVSS3: 5.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-48815

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-52v5-jr5w-gjxr

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.