CVE-2026-48816

MEDIUM

sigstore-js: Insufficient Verification of Data Authenticity

Title source: cna
STIX 2.1

Description

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 2.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-345
Status published
Products (1)
sigstore/sigstore-js < 3.1.1
Published Jul 14, 2026
Tracked Since Jul 15, 2026