sigstore

Security Scorecard

Score

92B

Total CVEs

7

Patch Rate

86%

6 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical0
High2
Medium5
Low0

Patch Status

Patched6 (86%)
Partial/Workaround0 (0%)
Unpatched1 (14%)

CVEs (7)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-24137Sigstore TUF Client Cache VulnerabilityMedium5.8-Patched
CVE-2026-23831Rekor PanicMedium5.30dUnpatched
CVE-2026-24117Rekor SSRF VulnerabilityMedium5.3-Patched
CVE-2026-22772Fulcio Code Signing Certificate SSRF VulnerabilityMedium5.8-Patched
CVE-2026-22703CVE-2026-22703Medium5.5-Patched
CVE-2025-66506Fulcio Certificate Authority VulnerabilityHigh7.5-Patched
CVE-2025-66564Sigstore Timestamp Authority Denial of ServiceHigh7.5-Patched