VDB
KO

GO-2026-5952

sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go

Quick fix

GO-2026-5952 — github.com/sigstore/sigstore-go: upgrade to the fixed version with the command below.

go get github.com/sigstore/sigstore-go@v1.2.0

Details

sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/sigstore/sigstore-go
Introduced in: 0 Fixed in: 1.2.0
Fix go get github.com/sigstore/sigstore-go@v1.2.0

References