HIGH🇵🇱 Wersja polska

CVE-2025-66564

CVSS 7.5v3.1pub. 2025-12-04upd. 2026-03-17

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to api.ParseJSONRequest or api.getContentType incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Linuxfoundation Sigstore Timestamp Authority

    APP
    Linuxfoundation
    < 2.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-49835MEDIUM5.9same product

Sigstore Timestamp Authority to usługa wydająca znaczniki czasu RFC 3161. Przed wersją 2.1.0 globalne middlewa...

CVE-2026-39984MEDIUM5.5same product

Sigstore Timestamp Authority to usługa wydająca znaczniki czasu RFC 3161. Wersje 2.0.5 i wcześniejsze zawieraj...

CVE-2026-53488CRITICAL9.4PL ✓same vendor

containerd CRI plugin: brak walidacji etykiet obrazu umożliwia RCE na hoście

CVE-2026-44477CRITICAL9.4PL ✓same vendor

CloudNativePG: eskalacja uprawnień do superużytkownika PostgreSQL przez metrics exporter

CVE-2026-37531CRITICAL9.8PL ✓same vendor

AGL app-framework-main: Zip Slip + TOCTOU umożliwiają zapis dowolnych plików