CVE-2026-49835General(linuxfoundation / sigstore_timestamp_authority)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/<uuid> or random HTTP methods and create unbounded permanent time-series entries that exhaust memory. This issue is fixed in version 2.1.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sigstore_timestamp_authority

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-17)
  • 3 total mentions across 2 days

Affected systems

Products
sigstore_timestamp_authority

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-30: 1Mentions · 2026-07-17: 2Technical Details · 2026-07-17: 106-3007-17
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-301
General1
2026-07-172
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-49835 Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path … https://www.cve.org/CVERecord?id=CVE-2026-49835 ----- Traducción: CVE-2026-49835 Sig… http://infoflow.cloud`

    Post summary

    The tweet only references CVE-2026-49835 with a link to the CVE record and a brief technical note, without any PoC, exploit code, or patch details.

    0000032
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-49835 Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path … https://www.cve.org/CVERecord?id=CVE-2026-49835

    Post summary

    The snippet notes CVE-2026-49835 in the Sigstore Timestamp Authority, mentioning a flaw where raw HTTP request paths were logged before v2.1.0, but offers no further detail on exploitation, patching, or mitigation.

    00000632
    57.8K followersView on X
  • DailyCVE@dailycve
    General

    🟠 Sigstore Timestamp Authority, Prometheus Label Cardinality DoS, #CVE-2026-49835 (Medium) -DC-Jun2026-758 https://dailycve.com/sigstore-timestamp-authority-prometheus-label-cardinality-dos-cve-2026-49835-medium-dc-jun2026-758/

    Post summary

    The text is a concise reference to the CVE-2026-49835 disclosure, offering no additional technical, exploit, or mitigation information.

    0000049
    217 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationsigstore_timestamp_authority---

Explore more