CVE-2026-49834
MediumAdvisory
Published 9 Jul 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.001
- 2nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 15
- of 17,781 indexed, latest versions
- Container images
- 15
- deployed by those charts
- Fix available
- 1 of 1
- affected package
sigstore-go has a multi-log threshold bypass via single compromised log
Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 15 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.7.2, v1.1.3, v1.1.4 | 1.2.0 | 15 |
- OSV records
- GHSA-9vcr-p3rj-q5q6
- Also known as
- GO-2026-5952
Charts affected
15 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| harborharborOfficialVerified publisher | 1.19.2 | 1 of 8See more | 1,650 |
| artifact-hubartifact-hubVerified publisher | 1.23.0 | 2 of 7See more | 10,755 |
| falcofalcosecurity | 9.1.0 | 2 of 3See more | 5,227 |
| connaisseurconnaisseurVerified publisher | 2.12.0 | 1 of 2See more | 3,012 |
| nuclionuclio | 0.23.8 | 1 of 2See more | 963 |
| local-ailocalai | 3.4.2 | 1 of 1See more | 3,997 |
| policy-controllersigstoreVerified publisher | 0.10.7 | 1 of 2See more | 911 |
| opikopikOfficialVerified publisher | 2.2.59 | 1 of 13See more | 14,334 |
| prowlerprowler-appVerified publisher | 0.0.9 | 1 of 5See more | 8,158 |
| harborgpg-dev | 1.18.3 | 1 of 8See more | 3,376 |
| harborhelm-harborVerified publisher | 2.3.5 | 1 of 8See more | 1,650 |
| osdfir-infrastructureosdfir-infrastructureVerified publisher | 2.15.0 | 1 of 40See more | 71,208 |
| sigstore-probersigstoreVerified publisher | 0.3.1 | 1 of 1See more | 424 |
| tufsigstoreVerified publisher | 0.1.32 | 1 of 1See more | 761 |
| harborwenerme | 1.19.2 | 1 of 8See more | 1,650 |
Container images carrying it
15 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| goharbor/ | 215c07b71c37 | github.com/ | 1.2.0 | 3 |
| aquasec/ | bcc376de8d77 | github.com/ | 1.2.0 | 1 |
| artifacthub/ | 2d8365601f0e | github.com/ | 1.2.0 | 1 |
| falcosecurity/ | 0eeb79adc580 | github.com/ | 1.2.0 | 1 |
| falcosecurity/ | 7df783d5269a | github.com/ | 1.2.0 | 1 |
| goharbor/ | 5c6f7162804c | github.com/ | 1.2.0 | 1 |
| prowlercloud/ | 4f252d579be2 | github.com/ | 1.2.0 | 1 |
| securesystemsengineering/ | 38918befbdad | github.com/ | 1.2.0 | 1 |
| ghcr.io/ | 269d0e55ea97 | github.com/ | 1.2.0 | 1 |
| ghcr.io/ | a6d5abe94706 | github.com/ | 1.2.0 | 1 |
| ghcr.io/ | 0bcd60beb93f | github.com/ | 1.2.0 | 1 |
| ghcr.io/ | ae8eb69c7b70 | github.com/ | 1.2.0 | 1 |
| ghcr.io/ | d1e914e6d6b9 | github.com/ | 1.2.0 | 1 |
| quay.io/ | d78cd113b2bc | github.com/ | 1.2.0 | 1 |
| quay.io/ | b5f5bd4efbee | github.com/ | 1.2.0 | 1 |