GHSA-273p-m2cw-6833
Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message
Quick fix
GHSA-273p-m2cw-6833 — github.com/sigstore/rekor: upgrade to the fixed version with the command below.
go get github.com/sigstore/rekor@v1.5.0Details
## Summary
Rekor’s cose v0.0.1 entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty `spec.message`. `validate()` returns nil (success) when `message` is empty, leaving `sign1Msg` uninitialized, and `Canonicalize()` later dereferences `v.sign1Msg.Payload`.
## Impact
A malformed proposed entry of the `cose/v0.0.1` type can cause a panic on a thread within the Rekor process. The thread is recovered so the client receives a 500 error message and service still continues, so the availability impact of this is minimal.
## Patches
Upgrade to v1.5.0
## Workarounds
None
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.5.0go get github.com/sigstore/rekor@v1.5.0References
- https://github.com/sigstore/rekor/security/advisories/GHSA-273p-m2cw-6833[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23831[ADVISORY]
- https://github.com/sigstore/rekor/commit/39bae3d192bce48ef4ef2cbd1788fb5770fee8cd[WEB]
- https://github.com/sigstore/rekor[PACKAGE]
- https://github.com/sigstore/rekor/releases/tag/v1.5.0[WEB]