StackRadar

CVE-2026-39984

Medium

Advisory

Published 14 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 2
affected packages

Sigstore Timestamp Authority has Improper Certificate Validation in verifier

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
github.com/sigstore/timestamp-authority/v2golangv2.0.32.0.64
github.com/sigstore/timestamp-authoritygolangv1.1.1, v1.1.2, v1.2.2, v1.2.5+1 moreno fix listed13
OSV records
GHSA-xm5m-wgh2-rrg3GO-2026-5763

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6

Open the chart page →

10,755
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6

Open the chart page →

3,997
policy-controllersigstoreVerified publisher0.10.71 of 2See more

policy-controller sigstore 0.10.7

1 of the 2 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
github.com/sigstore/timestamp-authority@v1.2.5
no fix listed

Open the chart page →

911
finops-stackcert-managerVerified publisher0.0.56 of 12See more

finops-stack cert-manager 0.0.5

6 of the 12 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

12,562
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

1,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.11 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/timestamp-authority@v1.1.1
no fix listed

Open the chart page →

7,087
harborgpg-dev1.18.31 of 8See more

harbor gpg-dev 1.18.3

1 of the 8 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6

Open the chart page →

3,376
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

1,893
agent-control-cdnewrelic1.0.01 of 3See more

agent-control-cd newrelic 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

5,034
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/timestamp-authority@v1.1.2
no fix listed

Open the chart page →

8,599
tufsigstoreVerified publisher0.1.321 of 1See more

tuf sigstore 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-39984.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/serverdigest-pinnedae8eb69c7b70
github.com/sigstore/timestamp-authority@v1.2.9
no fix listed

Open the chart page →

761

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/timestamp-authority@v1.1.1
no fix listed
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
github.com/sigstore/timestamp-authority@v1.2.5
no fix listed
1
ghcr.io/sigstore/scaffolding/serverae8eb69c7b70
github.com/sigstore/timestamp-authority@v1.2.9
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.0.6
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/timestamp-authority@v1.1.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.