StackRadar

CVE-2026-24137

Medium

Advisory

Published 22 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.8
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
26
of 17,781 indexed, latest versions
Container images
33
deployed by those charts
Fix available
1 of 1
affected package

sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal

Carried by container images the latest versions of 26 of 17,781 indexed charts deploy, on 33 images.

Affected packageAffected versionsFixed inImages
github.com/sigstore/sigstoregolangv0.0.0-20210722023421-fd3b69438dba, v1.0.2-0.20211210190220-04746d994282, v1.2.1-0.20220424143412-3d41663116d5, v1.5.1+10 more1.10.433
OSV records
GHSA-fcv2-xgw5-pqxf
Also known as
GO-2026-4358

Charts affected

26 by stars
ChartLatestAffected imagesRadar Score
artifact-hubartifact-hubVerified publisher1.23.01 of 7See more

artifact-hub artifact-hub 1.23.0

1 of the 7 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/sigstore/sigstore@v1.9.5
1.10.4

Open the chart page →

10,755
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
github.com/sigstore/sigstore@v1.9.5
1.10.4

Open the chart page →

1,339
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
github.com/sigstore/sigstore@v1.7.5
1.10.4

Open the chart page →

1,981
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/sigstore/sigstore@v1.10.0
1.10.4

Open the chart page →

3,997
fulciosigstoreVerified publisher2.11.11 of 6See more

fulcio sigstore 2.11.1

1 of the 6 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
github.com/sigstore/sigstore@v1.9.6-0.20250729224751-181c5d3339b3
1.10.4

Open the chart page →

3,490
policy-controllersigstoreVerified publisher0.10.71 of 2See more

policy-controller sigstore 0.10.7

1 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
github.com/sigstore/sigstore@v1.9.4
1.10.4

Open the chart page →

911
finops-stackcert-managerVerified publisher0.0.56 of 12See more

finops-stack cert-manager 0.0.5

6 of the 12 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/sigstore/sigstore@v1.8.3
1.10.4
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/sigstore/sigstore@v1.8.3
1.10.4
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/sigstore/sigstore@v1.8.3
1.10.4
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/sigstore/sigstore@v1.8.3
1.10.4
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/sigstore/sigstore@v1.8.3
1.10.4
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/sigstore/sigstore@v1.8.3
1.10.4

Open the chart page →

12,562
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/sigstore@v1.8.3
1.10.4

Open the chart page →

1,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.11 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/sigstore@v1.7.1
1.10.4

Open the chart page →

7,087
spirephilips-labsVerified publisher0.12.21 of 6See more

spire philips-labs 0.12.2

1 of the 6 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/sigstore/sigstore@v1.5.1
1.10.4

Open the chart page →

7,236
cosignedsigstoreVerified publisher0.1.232 of 2See more

cosigned sigstore 0.1.23

2 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
gcr.io/projectsigstore/cosigneddigest-pinned784518ff3ee7
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4
gcr.io/projectsigstore/policy-webhookdigest-pinned82940e8c3e0d
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4

Open the chart page →

5,118
scaffoldsigstoreVerified publisher0.6.1141 of 15See more

scaffold sigstore 0.6.114

1 of the 15 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
github.com/sigstore/sigstore@v1.9.6-0.20250729224751-181c5d3339b3
1.10.4

Open the chart page →

7,710
artifact-hubsoftonic1.19.03 of 8See more

artifact-hub softonic 1.19.0

3 of the 8 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
artifacthub/hub:v1.19.0111918d8c399
github.com/sigstore/sigstore@v1.8.3
1.10.4
artifacthub/scanner:v1.19.0323d026e78c3
github.com/sigstore/sigstore@v1.8.3
1.10.4
artifacthub/tracker:v1.19.06596c8c4d955
github.com/sigstore/sigstore@v1.8.3
1.10.4

Open the chart page →

14,491
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
github.com/sigstore/sigstore@v1.8.14
1.10.4

Open the chart page →

6,162
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4

Open the chart page →

4,722
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/sigstore/sigstore@v1.7.1
1.10.4

Open the chart page →

1,736
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
github.com/sigstore/sigstore@v1.9.5
1.10.4

Open the chart page →

2,420
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/sigstore@v1.8.3
1.10.4

Open the chart page →

1,893
agent-control-cdnewrelic1.0.01 of 3See more

agent-control-cd newrelic 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/sigstore@v1.8.12
1.10.4

Open the chart page →

5,034
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/sigstore@v1.0.2-0.20211210190220-04746d994282
1.10.4

Open the chart page →

8,599
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/sigstore/sigstore@v1.8.9
1.10.4

Open the chart page →

1,837
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/sigstore/sigstore@v1.7.5
1.10.4

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/sigstore/sigstore@v0.0.0-20210722023421-fd3b69438dba
1.10.4

Open the chart page →

29,227
ctlogsigstoreVerified publisher0.2.681 of 4See more

ctlog sigstore 0.2.68

1 of the 4 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
github.com/sigstore/sigstore@v1.9.6-0.20250729224751-181c5d3339b3
1.10.4

Open the chart page →

2,728
tufsigstoreVerified publisher0.1.321 of 1See more

tuf sigstore 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/serverdigest-pinnedae8eb69c7b70
github.com/sigstore/sigstore@v1.9.6-0.20250729224751-181c5d3339b3
1.10.4

Open the chart page →

761
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-24137.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
github.com/sigstore/sigstore@v1.9.5
1.10.4

Open the chart page →

1,787

Container images carrying it

33 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
github.com/sigstore/sigstore@v1.9.6-0.20250729224751-181c5d3339b3
1.10.4
3
artifacthub/hub:v1.19.0111918d8c399
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/sigstore/sigstore@v1.9.5
1.10.4
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/sigstore@v1.7.1
1.10.4
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
github.com/sigstore/sigstore@v1.8.14
1.10.4
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
github.com/sigstore/sigstore@v1.9.5
1.10.4
1
veecode/devportalc443520aebf7
github.com/sigstore/sigstore@v1.9.5
1.10.4
1
gcr.io/projectsigstore/cosigned784518ff3ee7
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
github.com/sigstore/sigstore@v1.7.5
1.10.4
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/sigstore@v1.8.12
1.10.4
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/sigstore/sigstore@v1.2.1-0.20220424143412-3d41663116d5
1.10.4
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/sigstore@v1.8.3
1.10.4
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
github.com/sigstore/sigstore@v1.9.4
1.10.4
1
ghcr.io/sigstore/scaffolding/serverae8eb69c7b70
github.com/sigstore/sigstore@v1.9.6-0.20250729224751-181c5d3339b3
1.10.4
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/sigstore/sigstore@v1.5.1
1.10.4
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/sigstore/sigstore@v1.10.0
1.10.4
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/sigstore/sigstore@v1.7.5
1.10.4
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/sigstore@v1.0.2-0.20211210190220-04746d994282
1.10.4
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
github.com/sigstore/sigstore@v1.9.5
1.10.4
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/sigstore/sigstore@v0.0.0-20210722023421-fd3b69438dba
1.10.4
1
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/sigstore/sigstore@v1.7.1
1.10.4
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/sigstore/sigstore@v1.8.9
1.10.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.