1. Sigstore TUF Client Vulnerability (CVE-2026-24137): Path Traversal Flaw Allows Arbitrary File Writes
A critical security flaw has been identified in the legacy TUF client within the widely-used Sigstore software supply chain security project. The vulnerability, tracked as CVE-2026-24137, allows for arbitrary file writes via a path traversal attack. The core failure is in the client's file caching mechanism, which cons...