| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-52v5-jr5w-gjxr | sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sigstore
Sigstore sigstore |
|
| Vendors & Products |
Sigstore
Sigstore sigstore |
Wed, 15 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 14 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1. | |
| Title | sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-15T12:56:29.848Z
Reserved: 2026-05-22T20:57:10.976Z
Link: CVE-2026-48815
Updated: 2026-07-15T12:56:12.729Z
Status : Deferred
Published: 2026-07-14T21:17:01.370
Modified: 2026-07-15T20:23:47.313
Link: CVE-2026-48815
OpenCVE Enrichment
Updated: 2026-07-31T05:00:05Z
Github GHSA