CVE-2020-13847: Sylabs Singularity

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.

Affected products

  • Sylabs Singularity: from 3.0.0, up to and including 3.5.0

Published 2020-07-14. Last modified 2026-06-17.