CVE-2026-24408 | sigstore sigstore-python up to 4.1.x OAuth Authentication _OAuthSession cross-site request forgery (GHSA-hm8f-75xx-w2vr / EUVD-2026-4729)
A vulnerability marked as problematic has been reported in sigstore sigstore-python up to 4.1.x. This issue affects the function _OAuthSession of the component OAuth Authentication. Performing a manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2026-24408. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.