CVE-2026-49835
MEDIUMSigstore Timestamp Authority: OOM due to unbounded metric label cardinality
Title source: cnaDescription
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/<uuid> or random HTTP methods and create unbounded permanent time-series entries that exhaust memory. This issue is fixed in version 2.1.0.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-9c54-x2g4-v92j
X_Refsource_Misc x_refsource_misc
https://github.com/sigstore/timestamp-authority/commit/506ec57b6ac2ea1e4739322e47453469425b69b5
X_Refsource_Misc x_refsource_misc
https://github.com/sigstore/timestamp-authority/releases/tag/v2.1.0
Scores
CVSS v3
5.9
EPSS
0.0043
EPSS Percentile
35.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (2)
linuxfoundation/sigstore_timestamp_authority
< 2.1.0
sigstore/timestamp-authority
< 2.1.0
Published
Jul 17, 2026
Tracked Since
Jul 18, 2026