Hayden
14 exploits
Active since Apr 2024
sigstore-go fails to check signature timestamps against a signing key's validity period
CVSS 3.1
sigstore-go: Multi-log threshold bypass via single compromised log
CVSS 5.9
Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality
CVSS 5.9
Mealie < 1.4.0 - Authenticated Server-Side Request Forgery via safe_scrape_html Function
CVSS 4.1
Mealie < 1.4.0 - Server-Side Request Forgery via Recipe Image Scraping
CVSS 6.2
sigstore cosign < 3.0.5 - Improper Certificate Validation
CVSS 3.7
Mealie < 1.4.0 - Denial of Service via Uncontrolled Resource Consumption in safe_scrape_html
CVSS 6.5
Mealie < 1.4.0 - Denial of Service via Image Request Resource Exhaustion
CVSS 6.5
Sigstore Timestamp Authority <2.0.3 - Info Disclosure
CVSS 7.5
sigstore cosign < 2.6.2 and 3.0.4 - Insufficient Verification of Data Authenticity
CVSS 5.5
Fulcio < 1.8.5 - Server-Side Request Forgery via MetaIssuer URL Validation Bypass
CVSS 5.8
Rekor <1.4.3 - Nil Pointer Dereference
CVSS 5.3
Rekor < 1.5.0 - Server-Side Request Forgery via Public Key Retrieval Endpoint
CVSS 5.3
sigstore framework <1.10.3 - Buffer Overflow
CVSS 5.8