Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-39395

Опубликовано: 07 апр. 2026
Источник: debian
EPSS Низкий

Описание

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cosignfixed2.6.3-1package
cosignno-dsatrixiepackage
golang-github-sigstore-cosign-v2fixed2.6.3-2package

Примечания

  • https://github.com/sigstore/cosign/security/advisories/GHSA-w6c6-c85g-mmv6

  • Fixed by: https://github.com/sigstore/cosign/commit/f1ad3ee952313be5d74a49d67ba0aa8d0d5e351f (v3.0.6)

  • Fixed by: https://github.com/sigstore/cosign/commit/fecddd3c22045a39f52392e71e79f66854b41352 (v2.6.3)

EPSS

Процентиль: 15%
0.00241
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
4 месяца назад

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

CVSS3: 6.5
redhat
4 месяца назад

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

CVSS3: 4.3
nvd
4 месяца назад

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

suse-cvrf
около 2 месяцев назад

Security update for cosign

suse-cvrf
2 месяца назад

Security update for cosign

EPSS

Процентиль: 15%
0.00241
Низкий