What is CVE-2026-54787?
CVE-2026-54787 is a vulnerability in the sigstore-go library. Prior to version 1.2.1, it fails to check a bundle signing timestamp against the validity window of a self-managed long-lived signing key without a certificate, which could allow an attacker to exploit an expired key. Users are advised to update to version 1.2.1.
Azərbaycanca: CVE-2026-54787 sigstore-go kitabxanasında aşkarlanmış boşluqdur. 1.2.1 versiyasından əvvəlki versiyalarda, sertifikatsız özünüidarə edən uzunmüddətli açar üçün bundle imzalama timestamp-i etibarlılıq müddəti ilə yoxlanılmır, bu da müddəti bitmiş açarla hücum edən şəxsə imkan yarada bilər. İstifadəçilərə 1.2.1 versiyasına yeniləmək tövsiyə olunur.
FAQ2
In which library was CVE-2026-54787 discovered?
CVE-2026-54787 was discovered in the sigstore-go library.
Which version is recommended to update to in order to mitigate this vulnerability?
Users are advised to update the sigstore-go library to version 1.2.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.