6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/sigstore/sigstore-go is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.1
CVE-2026-54787
sigstore-go fails to check signature timestamps against a signing key's validity period
MEDIUM 5.9
CVE-2026-49834
sigstore-go has a multi-log threshold bypass via single compromised log
LOW 3.1
CVE-2024-45395
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack
UNKNOWN
CVE-2026-54787
sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go
UNKNOWN
CVE-2026-49834
sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go
UNKNOWN
CVE-2024-45395
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes