{"id":"GHSA-jfc7-64v2-mr8c","summary":"@sigstore/core has DSSE payloadType type-binding failure","details":"### Impact\nThe `preAuthEncoding` function in `@sigstore/core` uses Node.js `'ascii'` encoding when converting the PAE (Pre-Authentication Encoding) string to bytes. This allows `payloadType` to be mutated after signing without invalidating the signature, breaking the type-binding guarantee that DSSE is designed to provide.\n\nIn `packages/core/src/dsse.ts`, the PAE function builds a string containing `payloadType` and then encodes it with `Buffer.from(prefix, 'ascii')`.\n\nIn Node.js, `'ascii'` encoding for string-to-Buffer is equivalent to `'latin1'`, which **truncates characters above U+00FF to their low byte**. This means for any ASCII character, there exist Unicode characters (at U+01xx, U+02xx, etc.) that produce the identical encoded byte:\n\n| Original | Codepoint | Mutant | Codepoint | Encoded byte |\n|----------|-----------|--------|-----------|--------------|\n| `t`      | U+0074    | `Ŵ`    | U+0174    | `0x74`       |\n| `e`      | U+0065    | `ť`    | U+0165    | `0x65`       |\n\nAn attacker can substitute every character in `payloadType` with a Unicode variant whose low byte matches, producing **identical PAE bytes** and a passing signature verification.\n\nAdditionally, `payloadType.length` returns the JavaScript string length (UTF-16 code units) rather than the UTF-8 byte length required by the DSSE spec, though this is only a contributing factor for non-ASCII types.\n\n#### Reproduction\n\n```javascript\nconst { preAuthEncoding } = require('@sigstore/core/dist/dsse.js');\nconst payload = Buffer.from('hello world');\n\nconst original = preAuthEncoding('text/plain', payload);\n// U+01xx chars whose low bytes match the original ASCII chars\nconst mutant = preAuthEncoding('\\u0174\\u0165\\u0178\\u0174/\\u0170\\u016c\\u0161\\u0169\\u016e', payload);\n\nconsole.log('PAE bytes equal:', original.equals(mutant)); // true — should be false\n```","aliases":["CVE-2026-48758"],"modified":"2026-08-24T00:36:56.719818445Z","published":"2026-06-26T19:11:19Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-26T19:11:19Z","nvd_published_at":null,"cwe_ids":["CWE-347"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/sigstore/sigstore-js/security/advisories/GHSA-jfc7-64v2-mr8c"},{"type":"PACKAGE","url":"https://github.com/sigstore/sigstore-js"}],"affected":[{"package":{"name":"@sigstore/core","ecosystem":"npm","purl":"pkg:npm/%40sigstore/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jfc7-64v2-mr8c/GHSA-jfc7-64v2-mr8c.json","last_known_affected_version_range":"\u003c= 3.2.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"}]}