Skip to content

Bump sigstore/timestamp-authority to v2.0.3+ to fix CVE-2025-66564 #2717

@vdemeester

Description

@vdemeester

Summary

CVE-2025-66564: Sigstore Timestamp Authority DoS via excessive OID or Content-Type header parsing.

Current State

  • main: v1.2.9
  • release-v0.42.0: v1.2.8
  • release-v0.37.2: v1.2.2

Required

Bump github.com/sigstore/timestamp-authority to v2.0.3+.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugCategorizes issue or PR as related to a bug.

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions