Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sigstore Go HIGH 7.5
CVE-2026-49834

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedC…

Fix: 1.2.0+
Fix from $1,950 2026-07-17
Cosign MEDIUM 5.3
CVE-2026-39395

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously r…

Fix: 2.6.3 / 3.0.6+
Fix from $1,600 2026-04-07
Sigstore HIGH 7.5
CVE-2026-31830

sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verif…

Fix: 0.2.3+
Fix from $1,950 2026-03-10
Cosign MEDIUM 5.5
CVE-2026-22703

Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to success…

Fix: 2.6.2 / 3.0.4+
Fix from $1,600 2026-01-10
Sigstore Go HIGH 7.5
CVE-2024-45395

sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verif…

Fix: 0.6.1+
Fix from $1,950 2024-09-04
Cosign HIGH 7.5
CVE-2024-29903

Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause d…

Fix: 2.2.4+
Fix from $1,950 2024-04-10
Cosign MEDIUM 5.9
CVE-2024-29902

Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cau…

Fix: 2.2.4+
Fix from $1,600 2024-04-10
Gitsign MEDIUM 5.3
CVE-2023-47122

Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fet…

Fix: 0.8.0+
Fix from $1,600 2023-11-10
Cosign MEDIUM 5.3
CVE-2023-46737

Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker wh…

Fix: 2.2.1+
Fix from $1,600 2023-11-07
Cosign MEDIUM 5.5
CVE-2022-36056

Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of v…

Fix: 1.12.0+
Fix from $1,600 2022-09-14
Policy Controller HIGH 8.8
CVE-2022-35930

PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a f…

Fix: 0.2.1+
Fix from $1,950 2022-08-04
Cosign CRITICAL 9.8
CVE-2022-35929

cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `co…

Fix: 1.10.1+
Fix from $2,300 2022-08-04