—
GO-2026-5952
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go
Quick fix
GO-2026-5952 — github.com/sigstore/sigstore-go: upgrade to the fixed version with the command below.
go get github.com/sigstore/sigstore-go@v1.2.0 Details
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/sigstore/sigstore-go
Introduced in:
0 Fixed in: 1.2.0 Fix
go get github.com/sigstore/sigstore-go@v1.2.0