Sigstore go: sigstore-go has a multi-log threshold bypass via single compromised log (CVE-2026-49834)
### Impact _What kind of vulnerability is it? Who is impacted?_ A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witnesses per-entry or per-validation-path rather than per-log-authority. As a result, a single compromised transparency log could forge multiple entries with different indices, and a single compromised CT log could verify multiple times (either across multiple certificate chains or via multiple embedded SCTs), fully satisfying the multi-log threshold requirements and defeating the multi-log policy. Note that this does not affect Cosign, as Cosign sets a threshold of 1. ### Patches _Has the problem been patched? What versions should users upgrade to?_ Upgrade to v1.1.5. ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There is no workaround, beyond relying on trusted logs.
AI Analysis
Technical Summary
The vulnerability in sigstore-go involves incorrect multi-log threshold verification logic when configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1). Instead of counting verified witnesses per log authority, the counting is done per entry or validation path, enabling a single compromised transparency log to forge multiple entries and satisfy multi-log threshold requirements. This defeats the intended defense-in-depth mechanism against single log compromise. Cosign is unaffected due to its threshold setting of 1. The issue is fixed in sigstore-go version 1.1.5.
Potential Impact
An attacker controlling a single compromised transparency log can bypass multi-log threshold protections, potentially allowing forged entries to be accepted as valid under multi-log policies. This undermines the defense-in-depth strategy designed to protect against single log compromises. There is no impact on confidentiality or availability, but integrity is affected due to the ability to forge entries. Cosign users are not impacted by this vulnerability.
Mitigation Recommendations
Upgrade sigstore-go to version 1.1.5 or later to apply the official fix. There is no known workaround other than relying on trusted transparency logs. Users should ensure they are not using affected versions prior to 1.2.0 with multi-log threshold configurations greater than 1.
Sigstore go: sigstore-go has a multi-log threshold bypass via single compromised log (CVE-2026-49834)
Description
### Impact _What kind of vulnerability is it? Who is impacted?_ A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witnesses per-entry or per-validation-path rather than per-log-authority. As a result, a single compromised transparency log could forge multiple entries with different indices, and a single compromised CT log could verify multiple times (either across multiple certificate chains or via multiple embedded SCTs), fully satisfying the multi-log threshold requirements and defeating the multi-log policy. Note that this does not affect Cosign, as Cosign sets a threshold of 1. ### Patches _Has the problem been patched? What versions should users upgrade to?_ Upgrade to v1.1.5. ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There is no workaround, beyond relying on trusted logs.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in sigstore-go involves incorrect multi-log threshold verification logic when configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1). Instead of counting verified witnesses per log authority, the counting is done per entry or validation path, enabling a single compromised transparency log to forge multiple entries and satisfy multi-log threshold requirements. This defeats the intended defense-in-depth mechanism against single log compromise. Cosign is unaffected due to its threshold setting of 1. The issue is fixed in sigstore-go version 1.1.5.
Potential Impact
An attacker controlling a single compromised transparency log can bypass multi-log threshold protections, potentially allowing forged entries to be accepted as valid under multi-log policies. This undermines the defense-in-depth strategy designed to protect against single log compromises. There is no impact on confidentiality or availability, but integrity is affected due to the ability to forge entries. Cosign users are not impacted by this vulnerability.
Mitigation Recommendations
Upgrade sigstore-go to version 1.1.5 or later to apply the official fix. There is no known workaround other than relying on trusted transparency logs. Users should ensure they are not using affected versions prior to 1.2.0 with multi-log threshold configurations greater than 1.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9vcr-p3rj-q5q6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-49834"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a50ba3c68715ace4357db1d
Added to database: 07/10/2026, 09:24:12 UTC
Last enriched: 07/18/2026, 11:18:58 UTC
Last updated: 07/31/2026, 21:28:40 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.