VDB
GO-2025-4192
GO-2025-4192
PUBLISHED
Sigstore Timestamp Authority allocates excessive memory during request parsing in github.com/sigstore/timestamp-authority
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | policy-controller-fips | 0, 0 |
| chainguard | cloudbeat-8.19 | 0, 0 |
| chainguard | vexctl | 0, 0 |
| wolfi | tkn | 0, 0, 0 |
| chainguard | image-factory-fips | 0, 0 |
| chainguard | ko-fips | 0, 0 |
| wolfi | zot | 0, 0, 0 |
| chainguard | tekton-chains-fips | 0, 0 |
| wolfi | kyverno-notation-aws | 0, 0, 0 |
| chainguard | chainctl | 0, 0 |
| wolfi | falcoctl | 0, 0, 0 |
| chainguard | kubescape | 0, 0 |
| chainguard | crossplane-fips-1.20 | 0, 0 |
| chainguard | crossplane-fips-2.1 | 0, 0 |
| wolfi | tflint | 0, 0, 0 |
| wolfi | crossplane-2.1 | 0, 0, 0 |
| wolfi | cosign | 0, 0, 0 |
| wolfi | policy-controller | 0, 0, 0 |
| chainguard | crossplane-fips-2.0 | 0, 0 |
| chainguard | neuvector-sigstore-interface-fips | 0, 0 |
…and 79 more
Timeline
- Dec 8, 2025 CVE Published
- Feb 4, 2026 CVE Updated
- May 1, 2026 Security Advisory