CVE-2026-54787: Sigstore Sigstore-Go

Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.

Affected products

  • Sigstore Sigstore-Go: before 1.2.1 (fixed in 1.2.1)

Published 2026-07-31. Last modified 2026-09-10.