
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23831 is a NULL Pointer Dereference vulnerability in Sigstore's Rekor software supply chain transparency log, affecting versions 1.4.3 and below. When processing a cose/v0.0.1 type entry with an empty spec.message, the validate() function incorrectly returns success without initializing sign1Msg, and the subsequent Canonicalize() call dereferences v.sign1Msg.Payload, triggering a panic. The vulnerability was discovered by researcher "1seal" and disclosed on January 22, 2026, with a fix released the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Rekor Advisory).
The root cause is a NULL Pointer Dereference (CWE-476) in the COSE v0.0.1 entry type implementation within pkg/types/cose/v0.0.1/entry.go. The validate() function returns nil (indicating success) when spec.message is empty, leaving the sign1Msg struct field uninitialized. When Canonicalize() is subsequently called, it dereferences v.sign1Msg.Payload without a nil check, causing a goroutine panic. The fix (commit 39bae3d) adds explicit nil guards for v.sign1Msg and v.sign1Msg.Payload in Canonicalize(), as well as nil checks for PublicKey in IndexKeys() and Unmarshal(), and a nil envelope check in the DSSE entry type (Rekor Advisory, Patch Commit).
Exploitation causes a goroutine panic within the Rekor server process when processing a malformed cose/v0.0.1 entry submission. Because Go's runtime recovers the panicking goroutine, the affected client receives an HTTP 500 error and the service continues operating normally — there is no process termination or persistent denial of service. There is no confidentiality or integrity impact; the vulnerability is limited to a transient, minimal availability disruption (Github Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation (Github Advisory). The vulnerability requires no authentication and no user interaction, making it trivially triggerable by any network-accessible attacker who can submit entries to a Rekor instance. The EPSS score is approximately 0.019% (0.000320 per Feedly), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
cose/v0.0.1 type proposed entry payload where spec.message is set to an empty value (e.g., empty string or omitted field), while providing other required fields such as a public key.POST /api/v1/log/entries) with the crafted payload.validate() function accepts the empty message without error, leaving sign1Msg uninitialized. When Canonicalize() is called, it dereferences the nil v.sign1Msg.Payload, triggering a goroutine panic./api/v1/log/entries with cose/v0.0.1 type entries containing an empty or missing spec.message field from unexpected or external IP addresses.Canonicalize or sign1Msg.The primary remediation is to upgrade Rekor to version 1.5.0 or later, which adds nil pointer guards in Canonicalize(), IndexKeys(), and Unmarshal() for the COSE and DSSE entry types (Rekor v1.5.0 Release, Patch Commit). No official workarounds are available for those unable to upgrade immediately; however, organizations should consider implementing network-level access controls to restrict who can submit entries to the Rekor API, and monitor logs for elevated 500 error rates on entry submission endpoints (Github Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."