Threat Advisory

Credential Confusion in Sigstore OCI Leaks Registry Credentials

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-59891 with a CVSS score of 9.6 is a credential confusion issue in @sigstore/oci that can leak registry credentials to an attacker-controlled registry when any consumer of the package uploads artifacts to an OCI registry using credentials from a Docker config, where the destination registry/image reference can be influenced by an untrusted party. This includes @actions/attest and the actions/attest, attest-build-provenance, and attest-sbom GitHub Actions when run with push-to-registry: true, where the subject-name input determines the destination registry. The vulnerability with affected versions ** `<= 0 is classified as critical given the potential to expose long-lived registry credentials, but exploitation requires all of the following: the Docker config on the host contains credentials for a registry; the destination registry/image reference is influenced by an untrusted source; and the attacker controls a registry whose hostname is a substring of or otherwise contained within a configured Docker auth key. Under those conditions, registry credentials present on the host can be sent to an attacker-controlled registry during the authentication exchange. Affected versions include all releases from 0.1.0 up to but not including 0.7.1.

RECOMMENDATION:

We recommend you to update @sigstore/oci to version 0.7.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-59891 with a CVSS score of 9.6 is a credential confusion issue in @sigstore/oci that can leak registry credentials to an attacker-controlled registry when any consumer of the package uploads artifacts to an OCI registry using credentials from a Docker config, where the destination registry/image reference can be influenced by an untrusted party. This includes @actions/attest and the actions/attest, attest-build-provenance, and attest-sbom GitHub Actions when run with push-to-registry: true, where the subject-name input determines the destination registry. The vulnerability with affected versions ** `<= 0 is classified as critical given the potential to expose long-lived registry credentials, but exploitation requires all of the following: the Docker config on the host contains credentials for a registry; the destination registry/image reference is influenced by an untrusted source; and the attacker controls a registry whose hostname is a substring of or otherwise contained within a configured Docker auth key. Under those conditions, registry credentials present on the host can be sent to an attacker-controlled registry during the authentication exchange. Affected versions include all releases from 0.1.0 up to but not including 0.7.1.

RECOMMENDATION:

We recommend you to update @sigstore/oci to version 0.7.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu