CVE-2026-48815: sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
The documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48815 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →