cvedb.io
CVE-2026-39395
MEDIUM · CVSS 4.3
EPSS exploitation probability: 0%
Published 2026-04-07T20:16:33.140 · Last modified 2026-06-17T10:42:02.837

Summary

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

Affected products

sigstore — cosign

Does this affect you?

Add your gear to cvedb and we'll alert you only when sigstore ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.