sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
- Severity:
- High
Description
The documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked.
Recommendation
Update the sigstore package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.1.0
- Patched version(s): 4.1.1
References
Related Issues
- Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` - CVE-2026-47200
- Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code - CVE-2026-33943
- OneUptime has WhatsApp Resend Verification Authorization Bypass - CVE-2026-30959
- Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS - CVE-2026-41150
You might also like:
- Tags:
- npm
- sigstore
Anything's wrong? Let us know Last updated on July 01, 2026


