CyberRota Analysis
AI-GeneratedThe Sigstore Timestamp Authority service prior to version 2.1.0 is vulnerable to unauthenticated remote attacks that can exploit the global wrapMetrics middleware, allowing attackers to generate unbounded time-series entries by sending arbitrary HTTP request paths and methods. This could lead to memory exhaustion and service disruption. Organizations using affected versions should prioritize upgrading to version 2.1.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/<uuid> or random HTTP methods and create unbounded permanent time-series entries that exhaust memory. This issue is fixed in version 2.1.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)