Description
The documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked.
Recommendation
Update the sigstore package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.1.0
- Patched version(s): 4.1.1
References
Could your website be exposed too?
SmartScanner can check your website for sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` - CVE-2026-47200
- Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code - CVE-2026-33943
- OneUptime has WhatsApp Resend Verification Authorization Bypass - CVE-2026-30959
- Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS - CVE-2026-41150


