MEDIUM5.5Go
GHSA-whqx-f9j3-ch6m· BIT-cosign-2026-22703, CVE-2026-22703Cosign verification accepts any valid Rekor entry under certain conditions
Modified: 9/10/2026
package
pkg:go/github.com/sigstore/cosign/v3
Cosign verification accepts any valid Rekor entry under certain conditions
Modified: 9/10/2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign
Modified: 8/24/2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign
Modified: 6/16/2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign
Modified: 6/27/2026