Skip to main content

Vendor/product archive

linuxfoundation / sigstore_timestamp_authority CVEs

Beta · best-effort

3 CVEs tagged to linuxfoundation / sigstore_timestamp_authority0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-49835

Published Jul 17, 2026

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-39984

Published Apr 15, 2026

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse fu…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1