github.com/sigstore/cosign/v2
Code signing and transparency for containers and binaries
Activity
- Latest release
- 1mo ago
- Total releases
- 29
- Cadence
- ~44 days
- Last 12 months
- 4
Reach
- Stars
- 6.2k
Details
- First release
- Dec 14, 2022
| Version | Released | |
|---|---|---|
v2.6.5
patch
1 CVE
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev |
v2.6.5
patch
Dependencies (61)
+ 53 more |
|
v2.6.4
patch
1 CVE
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev |
v2.6.4
patch
Dependencies (61)
+ 53 more |
|
v2.6.3
patch
1 CVE
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev |
v2.6.3
patch
Dependencies (61)
+ 53 more |
|
v2.6.2
patch
2 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev |
v2.6.2
patch
Dependencies (61)
+ 53 more |
|
v2.6.1
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.6.1
patch
Dependencies (61)
+ 53 more |
|
v2.6.0
minor
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.6.0
minor
Dependencies (61)
+ 53 more |
|
v2.5.3
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.5.3
patch
Dependencies (59)
+ 51 more |
|
v2.5.2
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.5.2
patch
Dependencies (59)
+ 51 more |
|
v2.5.1
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.5.1
patch
Dependencies (59)
+ 51 more |
|
v2.5.0
minor
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.5.0
minor
Dependencies (58)
+ 50 more |
|
v2.4.3
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.4.3
patch
Dependencies (58)
+ 50 more |
|
v2.4.2
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.4.2
patch
Dependencies (58)
+ 50 more |
|
v2.4.1
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.4.1
patch
Dependencies (58)
+ 50 more |
|
v2.4.0
minor
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.4.0
minor
Dependencies (58)
+ 50 more |
|
v2.3.0
minor
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.3.0
minor
Dependencies (55)
+ 47 more |
|
v2.2.4
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev |
v2.2.4
patch
Dependencies (55)
+ 47 more |
|
v2.2.3
patch
5 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.3
patch
Dependencies (54)
+ 46 more |
|
v2.2.2
patch
5 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.2
patch
Dependencies (54)
+ 46 more |
|
v2.2.1
patch
5 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.1
patch
Dependencies (54)
+ 46 more |
|
v2.2.0
minor
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.0
minor
Dependencies (54)
+ 46 more |
|
v2.1.1
patch
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (55)
+ 47 more |
|
v2.1.0
minor
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (55)
+ 47 more |
|
v2.0.2
patch
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.2
patch
Dependencies (48)
+ 40 more |
|
v2.0.1
patch
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.1
patch
Dependencies (48)
+ 40 more |
|
v2.0.0
initial
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0
initial
Dependencies (47)
+ 39 more |
|
v2.0.0-rc.3
pre
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0-rc.3
pre
Dependencies (47)
+ 39 more |
|
v2.0.0-rc.2
pre
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0-rc.2
pre
Dependencies (47)
+ 39 more |
|
v2.0.0-rc.1
pre
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0-rc.1
pre
Dependencies (47)
+ 39 more |
|
v2.0.0-rc.0
pre
6 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
2.6.3
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
2.6.2
References Updated Aug 24, 2026 · Source: OSV.dev
CVE-2024-29902
GO-2024-2718
BIT-cosign-2024-29902
GHSA-88jx-383q-w4qc
Jun 05, 2024
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-29903
GO-2024-2719
BIT-cosign-2024-29903
GHSA-95pr-fxf5-86gv
Jun 05, 2024
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign Fixed in
2.2.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-46737
GO-2023-2181
BIT-cosign-2023-46737
GHSA-vfp6-jrw2-99g9
Nov 09, 2023
Denial of service attack from remote registry in github.com/sigstore/cosign An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack. Fixed in
2.2.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0-rc.0
pre
Dependencies (47)
+ 39 more |