Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94425.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94425
Upstream
Published
2026-07-31T23:17:25Z
Modified
2026-09-10T14:16:58Z
Summary
CVE-2026-54787 affecting package gh for versions less than 2.97.0-1
Details

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.

References

Affected packages

Azure Linux:3 / gh

Package

Name
gh
Purl
pkg:rpm/azure-linux/gh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.97.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94425.json"