Skip to content

Open CVE in timestamp-authority #1587

@MondayHopscotch

Description

@MondayHopscotch

There is a recent vulnerability in the timestamp-authority package.

Our build caught it (we are slightly behind, but even the latest doesn't have the fix yet) :

NAME                                     INSTALLED  FIXED IN  TYPE       VULNERABILITY        SEVERITY  EPSS           RISK
github.com/sigstore/timestamp-authority  v1.2.5     2.0.3     go-module  GHSA-4qg8-fj49-pxjh  High      < 0.1% (11th)  < 0.1

https://ubuntu.com/security/CVE-2025-66564

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions