CVE-2026-23831: 
Datadog Agent vulnerability analysis and mitigation

Overview

CVE-2026-23831 is a NULL Pointer Dereference vulnerability in Sigstore's Rekor software supply chain transparency log, affecting versions 1.4.3 and below. When processing a cose/v0.0.1 type entry with an empty spec.message, the validate() function incorrectly returns success without initializing sign1Msg, and the subsequent Canonicalize() call dereferences v.sign1Msg.Payload, triggering a panic. The vulnerability was discovered by researcher "1seal" and disclosed on January 22, 2026, with a fix released the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Rekor Advisory).

Technical details

The root cause is a NULL Pointer Dereference (CWE-476) in the COSE v0.0.1 entry type implementation within pkg/types/cose/v0.0.1/entry.go. The validate() function returns nil (indicating success) when spec.message is empty, leaving the sign1Msg struct field uninitialized. When Canonicalize() is subsequently called, it dereferences v.sign1Msg.Payload without a nil check, causing a goroutine panic. The fix (commit 39bae3d) adds explicit nil guards for v.sign1Msg and v.sign1Msg.Payload in Canonicalize(), as well as nil checks for PublicKey in IndexKeys() and Unmarshal(), and a nil envelope check in the DSSE entry type (Rekor Advisory, Patch Commit).

Impact

Exploitation causes a goroutine panic within the Rekor server process when processing a malformed cose/v0.0.1 entry submission. Because Go's runtime recovers the panicking goroutine, the affected client receives an HTTP 500 error and the service continues operating normally — there is no process termination or persistent denial of service. There is no confidentiality or integrity impact; the vulnerability is limited to a transient, minimal availability disruption (Github Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation (Github Advisory). The vulnerability requires no authentication and no user interaction, making it trivially triggerable by any network-accessible attacker who can submit entries to a Rekor instance. The EPSS score is approximately 0.019% (0.000320 per Feedly), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Identify target: Locate a Rekor instance running version 1.4.3 or earlier, either a self-hosted deployment or a public-facing instance, using network scanning or service discovery.
  2. Craft malformed entry: Construct a cose/v0.0.1 type proposed entry payload where spec.message is set to an empty value (e.g., empty string or omitted field), while providing other required fields such as a public key.
  3. Submit the entry: Send the malformed proposed entry via an HTTP POST request to the Rekor entry submission API endpoint (e.g., POST /api/v1/log/entries) with the crafted payload.
  4. Trigger panic: The server's validate() function accepts the empty message without error, leaving sign1Msg uninitialized. When Canonicalize() is called, it dereferences the nil v.sign1Msg.Payload, triggering a goroutine panic.
  5. Observe result: The attacker receives an HTTP 500 response; the server recovers and continues operating. Repeated submissions can cause repeated transient errors for other users (Rekor Advisory, Patch Commit).

Indicators of compromise

  • Network: Repeated HTTP POST requests to /api/v1/log/entries with cose/v0.0.1 type entries containing an empty or missing spec.message field from unexpected or external IP addresses.
  • Logs: Elevated rate of HTTP 500 responses in Rekor access logs associated with entry submission endpoints; Go runtime panic/recovery log messages in the Rekor server logs referencing Canonicalize or sign1Msg.
  • Application Behavior: Unusual spike in 500 errors on the entry submission API without corresponding server crashes or restarts, indicating goroutine-level panics being recovered.

Mitigation and workarounds

The primary remediation is to upgrade Rekor to version 1.5.0 or later, which adds nil pointer guards in Canonicalize(), IndexKeys(), and Unmarshal() for the COSE and DSSE entry types (Rekor v1.5.0 Release, Patch Commit). No official workarounds are available for those unable to upgrade immediately; however, organizations should consider implementing network-level access controls to restrict who can submit entries to the Rekor API, and monitor logs for elevated 500 error rates on entry submission endpoints (Github Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

rekor: 1.5.0-1

Fixed

trixie

rekor

Affected

Ubuntu

Unknown

devel

rekor

Unknown

resolute

rekor

Unknown

resolute (esm-apps)

rekor

Unknown

RHEL / CentOS

Fixed

OpenShift

el9:odf4/cephcsi-rhel9-0:v4.22.0

Fixed

RHEL 9

rhel9/bootc-image-builder

Affected

RHEL 10

buildah.src

Affected

Source: This report was generated using AI

Related Datadog Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48702HIGH7.5
  • Datadog Agent logoDatadog Agent
  • docker-29
NoYesAug 13, 2026
CVE-2026-71557MEDIUM6.3
  • Packer logoPacker
  • rancher-fleet-0.13
NoYesAug 07, 2026
CVE-2026-61711MEDIUM5.3
  • Docker logoDocker
  • buildah
NoYesAug 19, 2026
CVE-2025-71405MEDIUM5.1
  • Datadog Agent logoDatadog Agent
  • rclone
NoYesAug 14, 2026
CVE-2026-61712LOW2.3
  • Docker logoDocker
  • skaffold-fips
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management