Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wqqc-jjcq-vfxm | sigstore-go fails to check signature timestamps against a signing key's validity period |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat hummingbird |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:/a:redhat:hummingbird:1 | |
| Vendors & Products |
Redhat
Redhat hummingbird |
|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 01 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sigstore
Sigstore sigstore-go |
|
| Vendors & Products |
Sigstore
Sigstore sigstore-go |
Fri, 31 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1. | |
| Title | sigstore-go fails to check signature timestamps against a signing key's validity period | |
| Weaknesses | CWE-324 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-31T23:36:13.441Z
Reserved: 2026-06-15T23:23:57.714Z
Link: CVE-2026-54787
Updated: 2026-07-31T23:36:08.101Z
Status : Received
Published: 2026-07-31T23:17:25.287
Modified: 2026-08-01T00:17:17.040
Link: CVE-2026-54787
OpenCVE Enrichment
Updated: 2026-08-04T22:30:05Z
Github GHSA