github.com/sigstore/rekor vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-48702Highgithub.com/sigstore/rekor: Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing LogicCVE-2026-24117Mediumgithub.com/sigstore/rekor: Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URLCVE-2026-23831Mediumgithub.com/sigstore/rekor: Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty MessageCVE-2023-33199Mediumgithub.com/sigstore/rekor: malformed proposed intoto entries can cause a panicCVE-2023-30551Highgithub.com/sigstore/rekor: Rekor's compressed archives can result in OOM conditions

Stop the waste.
Protect your environment with Kodem.