What is CVE-2026-48791?
CVE-2026-48791 is a critical vulnerability in sigstore-java version 2.0.0, where verification of the integrated Rekor entry time against the Fulcio certificate was erroneously removed. This flaw weakens the signature verification process, potentially allowing acceptance of artifacts signed with fraudulent certificates. Users must upgrade to version 2.1.0 or implement compensatory security controls.
Azərbaycanca: CVE-2026-48791 sigstore-java kitabxanasının 2.0.0 versiyasında baş verən kritik səhvdir — burada Rekor giriş vaxtının Fulcio sertifikatı ilə yoxlanması səhvən silinib. Bu zəiflik imza doğrulama mexanizmini zəiflədərək, saxta sertifikatlarla imzalanmış artifact-lərin qəbuluna səbəb ola bilər. İstifadəçilər mütləq 2.1.0 versiyasına yüksəlməli və ya alternativ təhlükəsizlik tədbirləri görməlidir.
FAQ2
Which library and version are affected by CVE-2026-48791?
CVE-2026-48791 is a critical vulnerability affecting version 2.0.0 of the sigstore-java library.
What action should be taken to remediate CVE-2026-48791?
To remediate this vulnerability, users must upgrade the sigstore-java library to version 2.1.0 or implement compensatory security controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.