CVE-2026-49834

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/07/2026
Last modified:
30/07/2026

Description

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a single compromised transparency log or CT log to satisfy multi-log threshold requirements and defeat the multi-log policy. This issue is fixed in version 1.2.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sigstore:sigstore-go:*:*:*:*:*:*:*:* 1.2.0 (excluding)