Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94425.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94425
Upstream
Published
2026-07-31T23:17:25Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-54787 affecting package gh 2.62.0-20
Details

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.

References

Affected packages

Azure Linux:3 / gh

Package

Name
gh
Purl
pkg:rpm/azure-linux/gh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.62.0-20

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94425.json"