WhisperX tag archive

#CVE-2026-39984

This page collects WhisperX intelligence signals tagged #CVE-2026-39984. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-14 08:22:45 · GitHub Issues

1. Sigstore Timestamp-Authority Verifier Exposes Authorization Bypass via Certificate Bag Manipulation (CVE-2026-39984)

A critical flaw in the Sigstore timestamp-authority verifier allows attackers to bypass authorization controls by manipulating the certificate bag. The vulnerability, tracked as CVE-2026-39984, resides in the `VerifyTimestampResponse` function within the `timestamp-authority/v2/pkg/verification` package. The function c...

The Lab · 2026-04-24 03:54:10 · GitHub Issues

2. CVE-2026-39984: Authorization Bypass in Sigstore Timestamp Authority Certificate Verification

A medium-severity authorization bypass vulnerability has been identified in Sigstore Timestamp Authority, affecting versions 2.0.5 and below. The flaw resides in the VerifyTimestampResponse function within the timestamp-authority/v2/pkg/verification package. The function correctly validates the certificate chain signat...