Package
reports-server
Component
github.com/sigstore/rekor
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
github.com/sigstore/rekor@v1.3.6 is a transitive dependency vendored via the sigstore/cosign chain. The vulnerability is a decompression bomb in rekor's server-side Alpine APK log-entry parsing (/api/v1/log/entries). reports-server does not run a rekor server and never invokes these endpoints. govulncheck binary-mode analysis of the shipped reports-server binary confirms no rekor symbols are reachable (dead-code-eliminated). The vulnerable code path is never executed.
Status