Cosign malicious attachments can cause system-wide denial of service
Modified: 9/10/2026
package
pkg:go/github.com/sigstore/cosign
Cosign malicious attachments can cause system-wide denial of service
Modified: 9/10/2026
Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature
Modified: 5/20/2024
Cosign malicious artifacts can cause machine-wide DoS
Modified: 9/10/2026
Improper Certificate Validation in Cosign
Modified: 12/6/2023
Cosign vulnerable to possible endless data attack from attacker-controlled registry
Modified: 9/10/2026
cosign's `cosign verify-attestaton --type` can report a false positive if any attestation exists
Modified: 12/6/2023
Cosign's verify-blob-attestation reports false positive when payload parsing fails
Modified: 9/10/2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped
Modified: 9/10/2026
Improper certificate validation in github.com/sigstore/cosign
Modified: 5/20/2024
Improper verification of signature attestations in github.com/sigstore/cosign
Modified: 5/20/2024
Improper blob verification in github.com/sigstore/cosign
Modified: 5/20/2024
Denial of service attack from remote registry in github.com/sigstore/cosign
Modified: 2/4/2026
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign
Modified: 2/4/2026
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign
Modified: 2/4/2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign
Modified: 8/24/2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign
Modified: 6/16/2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign
Modified: 6/27/2026