Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-49834 sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedC… Sigstore Go 1.2.0+ Fix from $1,9502026-07-17 MEDIUM 5.3 CVE-2026-39395 Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously r… Cosign 2.6.3 / 3.0.6+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-31830 sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verif… Sigstore 0.2.3+ Fix from $1,9502026-03-10 MEDIUM 5.5 CVE-2026-22703 Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to success… Cosign 2.6.2 / 3.0.4+ Fix from $1,6002026-01-10 HIGH 7.5 CVE-2024-45395 sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verif… Sigstore Go 0.6.1+ Fix from $1,9502024-09-04 HIGH 7.5 CVE-2024-29903 Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause d… Cosign 2.2.4+ Fix from $1,9502024-04-10 MEDIUM 5.9 CVE-2024-29902 Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cau… Cosign 2.2.4+ Fix from $1,6002024-04-10 MEDIUM 5.3 CVE-2023-47122 Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fet… Gitsign 0.8.0+ Fix from $1,6002023-11-10 MEDIUM 5.3 CVE-2023-46737 Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker wh… Cosign 2.2.1+ Fix from $1,6002023-11-07 MEDIUM 5.5 CVE-2022-36056 Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of v… Cosign 1.12.0+ Fix from $1,6002022-09-14 HIGH 8.8 CVE-2022-35930 PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a f… Policy Controller 0.2.1+ Fix from $1,9502022-08-04 CRITICAL 9.8 CVE-2022-35929 cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `co… Cosign 1.10.1+ Fix from $2,3002022-08-04