go

github.com/sigstore/cosign

View on go registry
17 Total advisories
17 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/sigstore/cosign is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 4.3
Go

CVE-2026-39395

Cosign's verify-blob-attestation reports false positive when payload parsing fails

LOW 3.7
Go

CVE-2026-24122

Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped

MEDIUM 4.2
Go

CVE-2024-29902

Cosign malicious attachments can cause system-wide denial of service

LOW 3.1
Go

CVE-2023-46737

Cosign vulnerable to possible endless data attack from attacker-controlled registry

MEDIUM 4.2
Go

CVE-2024-29903

Cosign malicious artifacts can cause machine-wide DoS

UNKNOWN
Go

CVE-2026-22703

Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign

UNKNOWN
Go

CVE-2026-39395

Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign

UNKNOWN
Go

CVE-2026-24122

Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign

UNKNOWN
Go

CVE-2023-46737

Denial of service attack from remote registry in github.com/sigstore/cosign

UNKNOWN
Go

CVE-2024-29902

Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign

UNKNOWN
Go

CVE-2024-29903

Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign

MEDIUM 5.5
Go

CVE-2022-36056

Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature

UNKNOWN
Go

CVE-2022-36056

Improper blob verification in github.com/sigstore/cosign

UNKNOWN
Go

CVE-2022-35929

Improper verification of signature attestations in github.com/sigstore/cosign

UNKNOWN
Go

CVE-2022-23649

Improper certificate validation in github.com/sigstore/cosign

HIGH 7.1
Go

CVE-2022-35929

cosign's `cosign verify-attestaton --type` can report a false positive if any attestation exists

LOW 3.3
Go

CVE-2022-23649

Improper Certificate Validation in Cosign

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes