GHSA-frqx-jfcm-6jjr
GitHub Security Advisory
malformed proposed intoto entries can cause a panic
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
### Impact
A malformed proposed entry of the `intoto/v0.0.2` type can cause a panic on a thread within the Rekor process. The thread is recovered so the client receives a 500 error message and service still continues, so the availability impact of this is minimal.
### Patches
This is fixed in v1.2.0 of Rekor.
### Workarounds
No
### References
Discovered by OSS-Fuzz
Affected Packages
Go
github.com/sigstore/rekor
Affected versions:
0
(fixed in 1.2.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 13, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.