CVE-2026-24137: 
Datadog Agent vulnerability analysis and mitigation

Overview

CVE-2026-24137 is a path traversal vulnerability in the legacy TUF client (pkg/tuf/client.go) of the sigstore Go framework, allowing a malicious TUF repository to trigger arbitrary file overwrites on affected systems. It affects github.com/sigstore/sigstore versions 1.10.3 and below; version 1.10.4 contains the fix. The vulnerability was published on January 22–23, 2026, and carries a CVSS v3.1 base score of 5.8 (Moderate) (Github Advisory, sigstore Advisory).

Technical details

The root cause is CWE-22 (Path Traversal): the legacy TUF client's diskCache struct constructs filesystem paths by joining a cache base directory with a target name sourced directly from signed TUF metadata using filepath.Join, without validating that the resulting path remains within the intended cache directory. An attacker controlling a TUF repository can craft signed metadata containing target names with path traversal sequences (e.g., ../../../etc/passwd), causing the client to write arbitrary content to locations outside the cache directory. The fix in commit 8ec410a introduces a safePath() helper that applies url.PathEscape() to the target name before joining, neutralizing traversal sequences (sigstore Commit, Github Advisory).

Impact

Successful exploitation allows a malicious TUF repository to overwrite arbitrary files on the filesystem of the process running the vulnerable client, limited only by that process's OS-level permissions. This could enable an attacker to corrupt configuration files, replace binaries, or plant malicious content, potentially leading to privilege escalation or persistent compromise of the affected host. Confidentiality and availability are not directly impacted; the primary risk is integrity loss. Affected parties include direct consumers of the sigstore/sigstore TUF client library and users of older Cosign versions; public Sigstore deployment users are unaffected due to quorum-based metadata validation (sigstore Advisory, Github Advisory).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). Exploitation requires the attacker to control or compromise a TUF repository that the victim client trusts, which represents a high-privilege precondition. The EPSS score is approximately 0.016% (4th percentile), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Control a malicious TUF repository: The attacker must operate or compromise a TUF repository that a target client is configured to trust (e.g., a private or mirror TUF repository).
  2. Craft malicious signed metadata: Create TUF target metadata containing a target name with path traversal sequences, such as ../../../etc/cron.d/malicious or ../../../home/user/.ssh/authorized_keys, and sign it with valid TUF keys for the repository.
  3. Serve the malicious metadata: Host the crafted TUF repository so that the vulnerable client fetches and processes the signed metadata.
  4. Trigger cache write: When the vulnerable sigstore/sigstore client (version ≤ 1.10.3) processes the metadata and attempts to cache the target file to disk, it calls filepath.Join(d.base, targetName) without sanitization, resolving the path outside the cache directory.
  5. Achieve arbitrary file write: The client writes attacker-controlled content to the traversed path (e.g., a cron job, SSH authorized key, or overwritten binary), limited to the permissions of the calling process (sigstore Advisory, sigstore Commit).

Indicators of compromise

  • File System: Unexpected files created or modified outside the sigstore TUF cache directory (typically ~/.sigstore/root/targets/ or a custom SIGSTORE_CACHE_DIR); files with names containing URL-encoded traversal sequences (e.g., ..%2F) in the cache directory indicating attempted exploitation that was blocked by a patched version.
  • Logs: Application or system logs showing file write operations to unexpected paths by the process consuming the sigstore library; errors related to os.MkdirAll or os.WriteFile in paths outside the expected cache base.
  • Process: Unexpected modification timestamps on sensitive files (e.g., /etc/cron.d/, ~/.ssh/authorized_keys, system binaries) coinciding with sigstore/Cosign client invocations.
  • Network: Connections from the affected host to unfamiliar or unauthorized TUF repository endpoints during sigstore client operations.

Mitigation and workarounds

Upgrade github.com/sigstore/sigstore to version 1.10.4 or later, which introduces path escaping via url.PathEscape() in the safePath() helper to prevent traversal (sigstore Release). As an immediate workaround without upgrading, set the environment variable SIGSTORE_NO_CACHE=true to disable disk caching in the legacy TUF client. The preferred long-term remediation is to migrate from the deprecated legacy TUF client to the new implementation at github.com/sigstore/sigstore-go/pkg/tuf. Additionally, ensure processes running the affected library operate with minimal filesystem permissions to limit the blast radius of any potential exploitation (Github Advisory).

Community reactions

The vulnerability was reported by security researcher 1seal and published by the sigstore maintainer Hayden-IO on January 22, 2026. The advisory notes that the legacy TUF client is already deprecated, and the maintainers recommend migration to the newer sigstore-go TUF implementation as the preferred long-term solution. Downstream distributions including SUSE, openSUSE, Fedora, Amazon Linux, and Red Hat have issued advisories and updates for affected packages (e.g., Cosign, vexctl, jfrog-cli) that bundle the vulnerable library (sigstore Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

golang-github-sigstore-sigstore: 1.10.4-1

Fixed

trixie

golang-github-sigstore-sigstore

Affected

Ubuntu

Unknown

devel

golang-github-sigstore-sigstore

Unknown

noble

golang-github-sigstore-sigstore

Unknown

noble (esm-apps)

golang-github-sigstore-sigstore

Unknown

resolute

golang-github-sigstore-sigstore

Unknown

resolute (esm-apps)

golang-github-sigstore-sigstore

Unknown

RHEL / CentOS

Affected

OpenShift

openshift4/oc-mirror-plugin-rhel8

Affected

RHEL 9

rhel9/bootc-image-builder

Affected

RHEL 10

buildah.src

Affected

Source: This report was generated using AI

Related Datadog Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48702HIGH7.5
  • Datadog Agent logoDatadog Agent
  • docker-29
NoYesAug 13, 2026
CVE-2026-71557MEDIUM6.3
  • Packer logoPacker
  • rancher-fleet-0.13
NoYesAug 07, 2026
CVE-2026-61711MEDIUM5.3
  • Docker logoDocker
  • buildah
NoYesAug 19, 2026
CVE-2025-71405MEDIUM5.1
  • Datadog Agent logoDatadog Agent
  • rclone
NoYesAug 14, 2026
CVE-2026-61712LOW2.3
  • Docker logoDocker
  • skaffold-fips
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management