sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when converting the PAE string to bytes, allowing payloadType to be mutated after signing without invalidating the signature and breaking the type-binding guarantee that DSSE is designed to provide. This issue is fixed in version 3.2.1.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade nodejs24Upgrade nodejs24-full-i18nUpgrade nodejs24-develUpgrade nodejs24-debuginfoUpgrade nodejs24-npmUpgrade v8-13.6-develUpgrade nodejs24-libsUpgrade nodejs24-debugsourceUpgrade nodejs24-docsUpgrade nodejs24-libs-debuginfo | Aug 10, 2026 | Jul 14, 2026 |
| Redhat_linux | — | No solution exists | Jul 20, 2026 | Jun 26, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub