Bug 2499691 (CVE-2026-49835) - CVE-2026-49835 timestamp-authority: Sigstore Timestamp Authority: Denial of Service via unbounded metric label cardinality
Summary: CVE-2026-49835 timestamp-authority: Sigstore Timestamp Authority: Denial of S...
Keywords:
Status: NEW
Alias: CVE-2026-49835
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-13 14:40 UTC by OSIDB Bzimport
Modified: 2026-07-14 15:42 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-13 14:40:38 UTC
The global wrapMetrics middleware in Sigstore Timestamp Authority records the raw HTTP request path and method as Prometheus labels. Since this runs before routing, unmatched paths and arbitrary methods create permanent time-series entries. An attacker can issue requests with random paths to exhaust system memory. Fixed in timestamp-authority v2.0.7/v2.1.0. Workaround: block invalid methods/paths at reverse proxy.


Note You need to log in before you can comment on or make changes to this bug.