PT-2026-2253 · Google+1 · Cosign+1

1Seal

·

Published

2026-01-01

·

Updated

2026-05-18

·

CVE-2026-22703

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cosign versions prior to 2.6.2 and 3.0.4
Description Cosign is a tool providing code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, a crafted Cosign bundle could successfully verify an artifact even if the embedded Rekor entry did not reference the artifact’s digest, signature, or public key. During Rekor entry verification, Cosign normally verifies the Rekor entry signature and compares the artifact's digest, the user's public key (from a Fulcio certificate or user-provided key), and the artifact signature to the Rekor entry contents. Without these comparisons, Cosign would accept any response from Rekor as valid. A malicious actor compromising a user’s identity or signing key could construct a valid Cosign bundle with an arbitrary Rekor entry, preventing the user from auditing the signing event.
Recommendations Update to Cosign version 2.6.2 or 3.0.4.

Exploit

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BIT-COSIGN-2026-22703
CLEANSTART-2026-BD19566
CLEANSTART-2026-EZ47382
CLEANSTART-2026-GK29346
CLEANSTART-2026-HF07497
CLEANSTART-2026-NS33477
CLEANSTART-2026-WB12909
CLEANSTART-2026-WN01990
CVE-2026-22703
GHSA-WHQX-F9J3-CH6M
GO-2026-4309
OPENSUSE-SU-2026:10232-1
OPENSUSE-SU-2026:20386-1
SUSE-SU-2026:0142-1
SUSE-SU-2026:0777-1
SUSE-SU-2026:20904-1

Affected Products

Cosign
Debian