<Vulnerability name="CVE-2026-54787">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-07-31T21:58:14</PublicDate>
    <Bugzilla id="2509939" url="https://bugzilla.redhat.com/show_bug.cgi?id=2509939" xml:lang="en:us">
github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>3.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-347</CWE>
    <Details xml:lang="en:us" source="Mitre">
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in sigstore-go, a software library used for verifying digital signatures. This vulnerability specifically affects the workflow for self-managed long-lived signing keys that do not use certificates. An attacker who possesses an expired signing key can exploit this by creating and signing software bundles that the system will incorrectly accept as valid. This bypasses the intended security checks, potentially leading to the acceptance of unauthorized or malicious software.
    </Details>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-07-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:44162">RHSA-2026:44162</Advisory>
        <Package name="spire1-15-main">spire1-15-main-1.15.2-0.3.hum1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-07-29T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:47889">RHSA-2026:47889</Advisory>
        <Package name="spire1-14-main">spire1-14-main-1.14.7-0.3.hum1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-07-29T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:47891">RHSA-2026:47891</Advisory>
        <Package name="trivy-main">trivy-main-0.72.0-0.1.3.hum1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Affected</FixState>
        <PackageName>cosign</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-54787
https://nvd.nist.gov/vuln/detail/CVE-2026-54787
https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f
https://github.com/sigstore/sigstore-go/pull/642
https://github.com/sigstore/sigstore-go/releases/tag/v1.2.1
https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm
    </References>
</Vulnerability>