PT-2026-2253 · Google+1 · Cosign+1
1Seal
·
Published
2026-01-01
·
Updated
2026-05-18
·
CVE-2026-22703
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cosign versions prior to 2.6.2 and 3.0.4
Description
Cosign is a tool providing code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, a crafted Cosign bundle could successfully verify an artifact even if the embedded Rekor entry did not reference the artifact’s digest, signature, or public key. During Rekor entry verification, Cosign normally verifies the Rekor entry signature and compares the artifact's digest, the user's public key (from a Fulcio certificate or user-provided key), and the artifact signature to the Rekor entry contents. Without these comparisons, Cosign would accept any response from Rekor as valid. A malicious actor compromising a user’s identity or signing key could construct a valid Cosign bundle with an arbitrary Rekor entry, preventing the user from auditing the signing event.
Recommendations
Update to Cosign version 2.6.2 or 3.0.4.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cosign
Debian