{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39984.json"
      }
    ],
    "title": "timestamp-authority/v2/pkg/verification: improper certificate validation in verifier",
    "tracking": {
      "current_release_date": "2026-08-17T16:13:09+00:00",
      "generator": {
        "date": "2026-08-17T16:13:09+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.16"
        }
      },
      "id": "CVE-2026-39984",
      "initial_release_date": "2026-04-14T23:41:47.909000+00:00",
      "revision_history": [
        {
          "date": "2026-04-14T23:41:47.909000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-24T16:43:17+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-17T16:13:09+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Advanced Cluster Security 4",
                "product": {
                  "name": "Red Hat Advanced Cluster Security 4",
                  "product_id": "red_hat_advanced_cluster_security_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Advanced Cluster Security 4"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Trusted Artifact Signer",
                "product": {
                  "name": "Red Hat Trusted Artifact Signer",
                  "product_id": "red_hat_trusted_artifact_signer",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Trusted Artifact Signer"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Security Profiles Operator",
                "product": {
                  "name": "Security Profiles Operator",
                  "product_id": "security_profiles_operator",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_security_profiles_operator:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Security Profiles Operator"
          },
          {
            "category": "product_version",
            "name": "advanced-cluster-security/rhacs-main-rhel8",
            "product": {
              "name": "advanced-cluster-security/rhacs-main-rhel8",
              "product_id": "advanced-cluster-security/rhacs-main-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/rhacs-main-rhel8?repository_url=registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "advanced-cluster-security/rhacs-rhel8-operator",
            "product": {
              "name": "advanced-cluster-security/rhacs-rhel8-operator",
              "product_id": "advanced-cluster-security/rhacs-rhel8-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/rhacs-rhel8-operator?repository_url=registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "advanced-cluster-security/rhacs-roxctl-rhel8",
            "product": {
              "name": "advanced-cluster-security/rhacs-roxctl-rhel8",
              "product_id": "advanced-cluster-security/rhacs-roxctl-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/rhacs-roxctl-rhel8?repository_url=registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
            "product": {
              "name": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
              "product_id": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/rhacs-scanner-v4-rhel8?repository_url=registry.redhat.io/advanced-cluster-security/rhacs-scanner-v4-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhtas/cosign-rhel9",
            "product": {
              "name": "rhtas/cosign-rhel9",
              "product_id": "rhtas/cosign-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/cosign-rhel9?repository_url=registry.redhat.io/rhtas/cosign-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhtas/ec-rhel9",
            "product": {
              "name": "rhtas/ec-rhel9",
              "product_id": "rhtas/ec-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/ec-rhel9?repository_url=registry.redhat.io/rhtas/ec-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhtas/gitsign-rhel9",
            "product": {
              "name": "rhtas/gitsign-rhel9",
              "product_id": "rhtas/gitsign-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/gitsign-rhel9?repository_url=registry.redhat.io/rhtas/gitsign-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compliance/openshift-security-profiles-operator-bundle",
            "product": {
              "name": "compliance/openshift-security-profiles-operator-bundle",
              "product_id": "compliance/openshift-security-profiles-operator-bundle",
              "product_identification_helper": {
                "purl": "pkg:oci/openshift-security-profiles-operator-bundle?repository_url=registry.redhat.io/compliance/openshift-security-profiles-operator-bundle"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compliance/openshift-security-profiles-rhel8-operator",
            "product": {
              "name": "compliance/openshift-security-profiles-rhel8-operator",
              "product_id": "compliance/openshift-security-profiles-rhel8-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/openshift-security-profiles-rhel8-operator?repository_url=registry.redhat.io/compliance/openshift-security-profiles-rhel8-operator"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "advanced-cluster-security/rhacs-main-rhel8 as a component of Red Hat Advanced Cluster Security 4",
          "product_id": "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-main-rhel8"
        },
        "product_reference": "advanced-cluster-security/rhacs-main-rhel8",
        "relates_to_product_reference": "red_hat_advanced_cluster_security_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "advanced-cluster-security/rhacs-rhel8-operator as a component of Red Hat Advanced Cluster Security 4",
          "product_id": "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-rhel8-operator"
        },
        "product_reference": "advanced-cluster-security/rhacs-rhel8-operator",
        "relates_to_product_reference": "red_hat_advanced_cluster_security_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "advanced-cluster-security/rhacs-roxctl-rhel8 as a component of Red Hat Advanced Cluster Security 4",
          "product_id": "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-roxctl-rhel8"
        },
        "product_reference": "advanced-cluster-security/rhacs-roxctl-rhel8",
        "relates_to_product_reference": "red_hat_advanced_cluster_security_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "advanced-cluster-security/rhacs-scanner-v4-rhel8 as a component of Red Hat Advanced Cluster Security 4",
          "product_id": "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-scanner-v4-rhel8"
        },
        "product_reference": "advanced-cluster-security/rhacs-scanner-v4-rhel8",
        "relates_to_product_reference": "red_hat_advanced_cluster_security_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhtas/cosign-rhel9 as a component of Red Hat Trusted Artifact Signer",
          "product_id": "red_hat_trusted_artifact_signer:rhtas/cosign-rhel9"
        },
        "product_reference": "rhtas/cosign-rhel9",
        "relates_to_product_reference": "red_hat_trusted_artifact_signer"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhtas/ec-rhel9 as a component of Red Hat Trusted Artifact Signer",
          "product_id": "red_hat_trusted_artifact_signer:rhtas/ec-rhel9"
        },
        "product_reference": "rhtas/ec-rhel9",
        "relates_to_product_reference": "red_hat_trusted_artifact_signer"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhtas/gitsign-rhel9 as a component of Red Hat Trusted Artifact Signer",
          "product_id": "red_hat_trusted_artifact_signer:rhtas/gitsign-rhel9"
        },
        "product_reference": "rhtas/gitsign-rhel9",
        "relates_to_product_reference": "red_hat_trusted_artifact_signer"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compliance/openshift-security-profiles-operator-bundle as a component of Security Profiles Operator",
          "product_id": "security_profiles_operator:compliance/openshift-security-profiles-operator-bundle"
        },
        "product_reference": "compliance/openshift-security-profiles-operator-bundle",
        "relates_to_product_reference": "security_profiles_operator"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compliance/openshift-security-profiles-rhel8-operator as a component of Security Profiles Operator",
          "product_id": "security_profiles_operator:compliance/openshift-security-profiles-rhel8-operator"
        },
        "product_reference": "compliance/openshift-security-profiles-rhel8-operator",
        "relates_to_product_reference": "security_profiles_operator"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-39984",
      "cwe": {
        "id": "CWE-295",
        "name": "Improper Certificate Validation"
      },
      "discovery_date": "2026-04-15T00:01:17.223168+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2458542"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in timestamp-authority, specifically in the timestamp-authority/v2/pkg/verification package. An attacker can exploit this issue by prepending a forged certificate to the certificate bag while the message is signed with an authorized key. This causes the library to validate the signature against one certificate but perform authorization checks against another, leading to an authorization bypass.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "timestamp-authority/v2/pkg/verification: improper certificate validation in verifier",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability allows an attacker to bypass authorization checks by prepending a forged certificate to the certificate bag. The library validates the signature against one certificate while performing authorization checks against another.\n\nAdditionally, a user or an automated system must actively run the `VerifyTimestampResponse` function against the attacker-supplied payload. Due to this reason, this flaw has been rated with a moderate severity.\n\nThis issue only impacts users of the `timestamp-authority/v2/pkg/verification` package and does not affect the `timestamp-authority` service or `sigstore-go`.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-main-rhel8",
          "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-rhel8-operator",
          "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-roxctl-rhel8",
          "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-scanner-v4-rhel8",
          "red_hat_trusted_artifact_signer:rhtas/cosign-rhel9",
          "red_hat_trusted_artifact_signer:rhtas/ec-rhel9",
          "red_hat_trusted_artifact_signer:rhtas/gitsign-rhel9",
          "security_profiles_operator:compliance/openshift-security-profiles-operator-bundle",
          "security_profiles_operator:compliance/openshift-security-profiles-rhel8-operator"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-39984"
        },
        {
          "category": "external",
          "summary": "RHBZ#2458542",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458542"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-39984",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39984"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-39984",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39984"
        },
        {
          "category": "external",
          "summary": "https://github.com/sigstore/timestamp-authority/releases/tag/v2.0.6",
          "url": "https://github.com/sigstore/timestamp-authority/releases/tag/v2.0.6"
        },
        {
          "category": "external",
          "summary": "https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-xm5m-wgh2-rrg3",
          "url": "https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-xm5m-wgh2-rrg3"
        }
      ],
      "release_date": "2026-04-14T23:41:47.909000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "To mitigate this vulnerability, users of VerifyTimestampResponse can use the TSACertificate option to explicitly specify the exact certificate they expect to be used.",
          "product_ids": [
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-main-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-rhel8-operator",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-roxctl-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-scanner-v4-rhel8",
            "red_hat_trusted_artifact_signer:rhtas/cosign-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/ec-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/gitsign-rhel9",
            "security_profiles_operator:compliance/openshift-security-profiles-operator-bundle",
            "security_profiles_operator:compliance/openshift-security-profiles-rhel8-operator"
          ]
        },
        {
          "category": "none_available",
          "details": "Fix deferred",
          "product_ids": [
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-main-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-rhel8-operator",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-roxctl-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-scanner-v4-rhel8",
            "red_hat_trusted_artifact_signer:rhtas/cosign-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/ec-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/gitsign-rhel9",
            "security_profiles_operator:compliance/openshift-security-profiles-operator-bundle",
            "security_profiles_operator:compliance/openshift-security-profiles-rhel8-operator"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-main-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-rhel8-operator",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-roxctl-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-scanner-v4-rhel8",
            "red_hat_trusted_artifact_signer:rhtas/cosign-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/ec-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/gitsign-rhel9",
            "security_profiles_operator:compliance/openshift-security-profiles-operator-bundle",
            "security_profiles_operator:compliance/openshift-security-profiles-rhel8-operator"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-main-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-rhel8-operator",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-roxctl-rhel8",
            "red_hat_advanced_cluster_security_4:advanced-cluster-security/rhacs-scanner-v4-rhel8",
            "red_hat_trusted_artifact_signer:rhtas/cosign-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/ec-rhel9",
            "red_hat_trusted_artifact_signer:rhtas/gitsign-rhel9",
            "security_profiles_operator:compliance/openshift-security-profiles-operator-bundle",
            "security_profiles_operator:compliance/openshift-security-profiles-rhel8-operator"
          ]
        }
      ],
      "title": "timestamp-authority/v2/pkg/verification: improper certificate validation in verifier"
    }
  ]
}