pkg:Go/github.com/sigstore/cosign
16 total CVEsHIGH2MEDIUM8LOW6
✅ Check your installed version
All known vulnerabilities
- from 0, < 1.10.1
- from 0, < 1.10.1
- from 0
- from 0, < 1.12.0
- from 0, < 1.12.0
- MEDIUM4.3CVE-2026-39395Cosign's verify-blob-attestation reports false positive when payload parsing fails>= 3.0.0, < 3.0.6
- from 0, <= 2.2.3
- from 0
- from 0, <= 2.2.3
- from 0
- LOW3.7CVE-2026-24122Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be Overlookedfrom 0
- LOW3.7CVE-2026-24122Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be Overlookedfrom 0, < 3.0.5
- from 0, < 1.5.2
- from 0, < 1.5.2
- LOW3.1CVE-2023-46737Cosign vulnerable to possible endless data attack from attacker-controlled registryfrom 0
- LOW3.1CVE-2023-46737Cosign vulnerable to possible endless data attack from attacker-controlled registryfrom 0, < 1.13.2