CVE Vulnerabilities

CVE-2026-54787

Use of a Key Past its Expiration Date

Published: Jul 31, 2026 | Modified: Aug 01, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.1 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.

Weakness

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Hardened ImagesRedHatspire1-15-main-1.15.2-0.3.hum1*
Red Hat Hardened ImagesRedHatspire1-14-main-1.14.7-0.3.hum1*
Red Hat Hardened ImagesRedHattrivy-main-0.72.0-0.1.3.hum1*
Sigstore-goUbuntuupstream*

Potential Mitigations

References