Description
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a single compromised transparency log or CT log to satisfy multi-log threshold requirements and defeat the multi-log policy. This issue is fixed in version 1.2.0.
Severity (CVSS)
| Base score | 5.9 |
|---|---|
| Severity | Medium |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
| Provided by | CNA |
Weaknesses
- CWE-347 — CWE-347: Improper Verification of Cryptographic Signature
Affected products
| Vendor | Product | Versions |
|---|---|---|
| sigstore | sigstore-go | < 1.2.0 |
References
- https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6 (x_refsource_CONFIRM)
- https://github.com/sigstore/sigstore-go/pull/633 (x_refsource_MISC)
- https://github.com/sigstore/sigstore-go/commit/dbb07e62623edd5b175fb9dd5a41dcb85a159207 (x_refsource_MISC)
- https://github.com/sigstore/sigstore-go/releases/tag/v1.2.0 (x_refsource_MISC)
Generated from the official CVE List on 18 Jul 2026 07:00 UTC.