CVE-2026-48816 Details
Description
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.
A vulnerability exists in the Sigstore-js library, specifically in the @sigstore/verify package, prior to version 3.1.1. The issue arises from improper handling of transparency-log timestamps, allowing an attacker to influence certificate validity and timestamp verification decisions. This vulnerability is present in versions of the library that include bundle v0.2, where the inclusion proof does not securely bind the integrated time, creating a trust gap that can be exploited.
Users are advised to update to version 3.1.1 of the @sigstore/verify package, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sigstore/sigstore-js/security/advisories/GHSA-xgjw-pm74-86q4 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/sigstore/sigstore-js/commit/f074710a91ea9260a9ac2142345634579843a3cd | [email protected] | Source CodeVendor |
| https://github.com/sigstore/sigstore-js/pull/1659 | [email protected] | Issue TrackingVendor |
| https://github.com/sigstore/sigstore-js/releases/tag/%40sigstore%2Fverify%403.1.1 | [email protected] | Release NotesVendor |
| https://github.com/sigstore/sigstore-js/security/advisories/GHSA-xgjw-pm74-86q4 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sigstore-js | < 3.1.1 (semver) |
CPE
Remediation
| |
| sigstore-js @sigstore/verify | 3.1.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion