sigstore sigstore-js是美国sigstore组织的一个JavaScript签名服务库。 sigstore-js 3.2.1之前版本存在加密问题漏洞,该漏洞源于preAuthEncoding函数使用Node.js ascii编码将PAE字符串转换为字节,可能允许签名后修改payloadType,从而破坏DSSE的类型绑定保证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| sigstore | sigstore-js | < 3.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sigstore | sigstore-js | < 3.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59891 | 9.6 CRITICAL | Credential confusion in @sigstore/oci can leak registry credentials to an attacker-contr |
| CVE-2026-48815 | 7.5 HIGH | sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enf |
| CVE-2026-48816 | 6.5 MEDIUM | sigstore-js: Insufficient Verification of Data Authenticity |
No comments yet