PT-2026-4280 · Rekor · Rekor

1Seal

·

Published

2026-01-22

·

Updated

2026-04-16

·

CVE-2026-23831

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Rekor versions 1.4.3 and below
Description Rekor’s entry implementation can experience a panic when processing attacker-controlled input during the canonicalization of a proposed entry with an empty spec.message. The validate() function incorrectly returns success when the message is empty, resulting in an uninitialized sign1Msg. Subsequently, the Canonicalize() function attempts to dereference v.sign1Msg.Payload, leading to a nil pointer dereference. A malformed proposed entry of the cose/v0.0.1 type can trigger this panic within the Rekor process. The service recovers from the panic, returning a 500 error to the client, minimizing the impact on availability.
Recommendations Upgrade to version 1.5.0.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-EZ47382
CLEANSTART-2026-GK29346
CLEANSTART-2026-WB12909
CVE-2026-23831
GHSA-273P-M2CW-6833
GO-2026-4354
OPENSUSE-SU-2026:10127-1
SUSE-SU-2026:0403-1

Affected Products

Rekor