CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54787

lowCVSS 3.1covered by 1 sourcefirst seen 2026-07-31
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.

⚡ Watch CVE-2026-54787

Get an email if CVE-2026-54787 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-54787

CVE.org record

Embed the live status

CVE-2026-54787 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54787 status](https://www.csirts.com/badge/CVE-2026-54787)](https://www.csirts.com/cve/CVE-2026-54787)