Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 98%

Sigstore go: sigstore-go has a multi-log threshold bypass via single compromised log (CVE-2026-49834)

0
Medium
Published: 07/09/2026 (07/09/2026, 23:20:30 UTC)
Source: GCVE Database
Product: github.com/sigstore/sigstore-go

Description

### Impact _What kind of vulnerability is it? Who is impacted?_ A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witnesses per-entry or per-validation-path rather than per-log-authority. As a result, a single compromised transparency log could forge multiple entries with different indices, and a single compromised CT log could verify multiple times (either across multiple certificate chains or via multiple embedded SCTs), fully satisfying the multi-log threshold requirements and defeating the multi-log policy. Note that this does not affect Cosign, as Cosign sets a threshold of 1. ### Patches _Has the problem been patched? What versions should users upgrade to?_ Upgrade to v1.1.5. ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There is no workaround, beyond relying on trusted logs.

CVSS v3.1

Score 5.9medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected software

Goghsa
github.com/sigstore/sigstore-go
Affected versions
<1.2.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/18/2026, 11:18:58 UTC

Technical Analysis

The vulnerability in sigstore-go involves incorrect multi-log threshold verification logic when configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1). Instead of counting verified witnesses per log authority, the counting is done per entry or validation path, enabling a single compromised transparency log to forge multiple entries and satisfy multi-log threshold requirements. This defeats the intended defense-in-depth mechanism against single log compromise. Cosign is unaffected due to its threshold setting of 1. The issue is fixed in sigstore-go version 1.1.5.

Potential Impact

An attacker controlling a single compromised transparency log can bypass multi-log threshold protections, potentially allowing forged entries to be accepted as valid under multi-log policies. This undermines the defense-in-depth strategy designed to protect against single log compromises. There is no impact on confidentiality or availability, but integrity is affected due to the ability to forge entries. Cosign users are not impacted by this vulnerability.

Mitigation Recommendations

Upgrade sigstore-go to version 1.1.5 or later to apply the official fix. There is no known workaround other than relying on trusted transparency logs. Users should ensure they are not using affected versions prior to 1.2.0 with multi-log threshold configurations greater than 1.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-9vcr-p3rj-q5q6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-49834"]
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a50ba3c68715ace4357db1d

Added to database: 07/10/2026, 09:24:12 UTC

Last enriched: 07/18/2026, 11:18:58 UTC

Last updated: 07/31/2026, 21:28:40 UTC

Views: 54

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses