{"api_version":"v1","generated_at":"2026-10-08T19:55:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-sigstore-timestamp-authority-fb1fe54c3a55","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"timestamp-authority","next_cursor":null,"observations":[{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2026-49835","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49835","fixed":"2.1.0.","last_modified":"2026-07-17T19:45:44.026Z","patch_url":"https://github.com/sigstore/timestamp-authority/commit/506ec57b6ac2ea1e4739322e47453469425b69b5","primary_source":"","published":"2026-07-17T18:16:41.764Z"},{"affected":"< 2.0.6","affected_versions_present":true,"cve_id":"CVE-2026-39984","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39984","fixed":"2.0.6.","last_modified":"2026-04-16T14:00:55.081Z","patch_url":"https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-xm5m-wgh2-rrg3","primary_source":"","published":"2026-04-14T23:41:47.909Z"},{"affected":"< 2.0.3","affected_versions_present":true,"cve_id":"CVE-2025-66564","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66564","fixed":"If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release.","last_modified":"2025-12-05T14:55:53.273Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-66564","primary_source":"","published":"2025-12-04T22:37:13.307Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"sigstore"}}
