Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39395

Опубликовано: 07 апр. 2026
Источник: nvd
CVSS3: 4.3
CVSS3: 5.3
EPSS Низкий

Описание

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*
Версия до 2.6.3 (исключая)
cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.6 (исключая)

EPSS

Процентиль: 15%
0.00241
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 4.3
ubuntu
4 месяца назад

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

CVSS3: 6.5
redhat
4 месяца назад

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

CVSS3: 4.3
debian
4 месяца назад

Cosign provides code signing and transparency for containers and binar ...

suse-cvrf
около 2 месяцев назад

Security update for cosign

suse-cvrf
2 месяца назад

Security update for cosign

EPSS

Процентиль: 15%
0.00241
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-754