Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-66564

24
FAUCET Score

CVE-2025-66564 affects the Sigstore Timestamp Authority prior to version 2.0.3, specifically within the api.ParseJSONRequest and api.getContentType functions. This vulnerability, rated 7.5 HIGH, is a denial-of-service (DoS) risk due to excessive memory allocation. An unauthenticated attacker can exploit this by submitting a malicious request with an overly long OID or a malformed Content-Type header, leading to O(n) byte allocations and potential service disruption. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.0.3CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:sigstore_timestamp_authority:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 13th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

gopatch availablevia ghsa
Product: github.com/sigstore/timestamp-authorityFixed in: 2.0.3
redhatpatch availablevia redhat_api
Product: OpenShift Security Profiles Operator 1Fixed in: compliance/openshift-security-profiles-rhel8-operator:sha256:66c78e05a610eb31b8a350502b778305e53da9576ae124a3eb7ab3cc29595297
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:f96217aeff1a39024700537986dca70ce7e94949c91c3da815dc715ef6588044
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:1324d938cf5047df9125eb4bf6a9565fc4443b62c24e34494c1f57d1f8b5bdb1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-rhel8-operator:sha256:1e9116742efaed46b4b93ba1ff8eb026ffa5bbe5146690d020389b95bec77051
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:25bb4a371c5656d01a53060df46b7fbb5a287fe843c08581be69fb42ff5ec5dd
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-rhel8-operator:sha256:817f1ffbf4d8917fdb02f33a5ffd72e16f73952897356cb4d21f1daf1b6e3d88
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.3Fixed in: rhtas/timestamp-authority-rhel9:sha256:37b9359f11098a781158e5bc0850ec43b599d29a354b43745067656b0a234814
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Security Profiles Operator 1Fixed in: compliance/openshift-security-profiles-operator-bundle:sha256:4604d631307390e44fea4729d87470a32f294f380b4c7c9448a8e1a82ccec5b7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.3Fixed in: rhtas/rhtas-console-rhel9:sha256:9178c9d48b3e6ac76f4f74b7bb60f450a5076de937ee8843e19cf4749449ecd8
View patch
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-opc-rhel9
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines-client
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-chains-controller-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-chains-controller-rhel9
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-cli-tkn-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-cli-tkn-rhel9
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-operator-bundle
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-operator-proxy-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-rhel8-operator
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-rhel9-operator
redhatno patchvia redhat_api
Product: OpenShift ServerlessFixed in: openshift-serverless-1/kn-plugin-event-sender-rhel9
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-operator-bundle
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/udi-rhel9
redhatno patchvia redhat_api
Product: Zero Trust Workload Identity Manager - Tech PreviewFixed in: zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-operator-bundle
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-operator-webhook-rhel8
redhatend of lifevia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-operator-proxy-rhel9
redhatend of lifevia redhat_api
Product: Zero Trust Workload Identity Manager - Tech PreviewFixed in: zero-trust-workload-identity-manager/spiffe-spire-server-rhel9
redhatend of lifevia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-operator-webhook-rhel9
redhatend of lifevia redhat_api
Product: Zero Trust Workload Identity Manager - Tech PreviewFixed in: zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9
redhatend of lifevia redhat_api
Product: Zero Trust Workload Identity Manager - Tech PreviewFixed in: zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9
redhatend of lifevia redhat_api
Product: Zero Trust Workload Identity Manager - Tech PreviewFixed in: zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9

Vendor Advisories (2)

goGHSA-4qg8-fj49-pxjhhigh

Sigstore Timestamp Authority allocates excessive memory during request parsing

Dec 5, 2025
redhatCVE-2025-66564Important

github.com/sigstore/timestamp-authority: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing

Dec 4, 2025

References

github.com / sigstore/timestamp-authority/commit/0cae34e197d685a14904e0bad135b89d13b69421
Patch
github.com / sigstore/timestamp-authority/security/advisories/GHSA-4qg8-fj49-pxjh
Vendor Advisory