← Back

CVE-2026-24408

nvd nist
Published: Jan 26, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 1.6 / Impact: 3.4
Source: NVD

Description

sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. `_OAuthSession` creates a unique "state" and sends it as a parameter in the authentication request but the "state" in the server response seems not not be cross-checked with this value. Version 4.2.0 contains a patch for the issue.

Affected (1)

Sigstore Python
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.2.0

References (3)

Timeline

No history available yet.