Israel[verified]@f1tym1Patch
CVE-2026-54787 in sigstore-go allows expired keys to sign code; the issue is addressed and fixed in version v1.2.1.
DailyCVE@dailycveDisclosure
A low‑severity CVE‑2026‑54787, concerning the use of an expired key in sigstore‑go, is disclosed without mention of exploitation, exploit tools, or remediation.
Infoflowcloud@infoflowcloudGeneral
The post identifies CVE‑2026‑54787 as a timestamp‑validation flaw in sigstore‑go but provides no information on exploitation, patching, or proof‑of‑concept.
CVE@CVEnewDisclosure
The passage discloses CVE-2026-54787, noting a missing timestamp verification in sigstore-go, but provides no exploit, PoC, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsPatch
The CVE-2026-54787 describes a timestamp validation bypass in sigstore-go, with the issue fixed in version 1.2.1; no PoC, exploit, or active exploitation details are provided.