{"apiVersion":"1.0","identifier":"CVE-2026-48791","description":"sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verification with enhancements that adhere to the Sigstore verification spec. The old sigstore-conformance test for this check was built incorrectly. This vulnerability impacts only users verifying bundles with `dev.sigstore:sigstore-java:2.0.0`. Older versions are not affected; it is fixed in `dev.sigstore:sigstore-java:2.1.0` A malicious actor may exploit this if they were able to access a users system and exfiltrate the temporary private key used during signing and then reuse an old fulcio certificate later without requiring direct access to the user-s credentials. Users may protect themselves by re-verifying their artifacts using the newest sigstore-java or another current sigstore client. Transparency logs may also be audited for unauthorized signatures for a suspected reused identity.","publishedAt":"2026-08-13T00:17:32","lastModifiedAt":"2026-08-13T13:19:09","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48791","cvssScore":2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","epssProbability":0.00056,"riskScore":0.2,"affectedProduct":"sigstore-java","affectedVersions":"==2.0.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-48791","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-48791","en":"https://www.redsauce.net/en/cves/CVE-2026-48791","fr":"https://www.redsauce.net/fr/cves/CVE-2026-48791","pt":"https://www.redsauce.net/pt/cves/CVE-2026-48791","de":"https://www.redsauce.net/de/cves/CVE-2026-48791","sk":"https://www.redsauce.net/sk/cves/CVE-2026-48791","el":"https://www.redsauce.net/el/cves/CVE-2026-48791"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-48791"}}