VendorsSigstorecosignall versions
Vulnerabilities

Sigstore Cosign

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-35929
False positive signature verification in cosign
Published 2022-08-04 · Modified
9.8EPSS 0.007
CVE-2024-29903
Cosign vulnerable to machine-wide denial of service via malicious artifacts
Published 2024-04-10 · Analyzed
7.5EPSS 0.009
CVE-2024-29902
Cosign vulnerable to system-wide denial of service via malicious attachments
Published 2024-04-10 · Analyzed
5.9EPSS 0.007
CVE-2022-36056
Vulnerabilities with blob verification in sigstore cosign
Published 2022-09-14 · Modified
5.5EPSS 0.002
CVE-2026-22703
Cosign verification accepts any valid Rekor entry under certain conditions
Published 2026-01-10 · Analyzed
5.5EPSS 0.001
CVE-2023-46737
Possible endless data attack from attacker-controlled registry in cosign
Published 2023-11-07 · Modified
5.3EPSS 0.006
CVE-2026-39395
Cosign's verify-blob-attestation reports false positive when payload parsing fails
Published 2026-04-07 · Analyzed
5.3EPSS 0.003
CVE-2026-24122
Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be Overlooked
Published 2026-02-19 · Analyzed
3.7EPSS 0.002
CVE-2022-23649
Improper Certificate Validation in Cosign
Published 2022-02-18 · Modified
3.3EPSS 0.002