Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-24408
January 26, 2026
sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. "_OAuthSession" creates a unique "state" and sends it as a parameter in the authentication request but the "state" in the server response seems not not be cross-checked with this value. Version 4.2.0 contains a patch for the issue.
Affected Packages
https://github.com/sigstore/sigstore-python.git (GITHUB):
Affected version(s) >=v0.0.1-pre.1 <v4.2.0
Fix Suggestion:
Update to version v4.2.0
sigstore (PYTHON):
Affected version(s) >=0.0.1rc1 <4.2.0
Fix Suggestion:
Update to version 4.2.0
Do you need more information?
Contact Us
Weakness Type (CWE)
Cross-Site Request Forgery (CSRF)
EPSS
Base Score:
0.01