sigstore sigstore-js是美国sigstore组织的一个JavaScript签名服务库。 sigstore sigstore-js 3.1.1之前版本存在输入验证错误漏洞,该漏洞源于透明日志时间戳的生成方式可能导致不受信任的捆绑包影响证书有效性和时间戳阈值验证决策。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| sigstore | sigstore-js | < 3.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sigstore | sigstore-js | < 3.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59891 | 9.6 CRITICAL | Credential confusion in @sigstore/oci can leak registry credentials to an attacker-contr |
| CVE-2026-48815 | 7.5 HIGH | sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enf |
| CVE-2026-48758 | 5.4 MEDIUM | sigstore-js: DSSE payloadType type-binding failure |
No comments yet