1. Sigstore Timestamp-Authority Verifier Exposes Authorization Bypass via Certificate Bag Manipulation (CVE-2026-39984)
A critical flaw in the Sigstore timestamp-authority verifier allows attackers to bypass authorization controls by manipulating the certificate bag. The vulnerability, tracked as CVE-2026-39984, resides in the `VerifyTimestampResponse` function within the `timestamp-authority/v2/pkg/verification` package. The function c...