CVE-2022-35930High· 7.1▾ TwilightPolicyController before 0.2.1 may bypass attestation verification
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
PolicyController will report a false positive, resulting in an admission when it should not be admitted when:
Users should upgrade to cosign version 0.2.1 or greater for a patch. There are no known workarounds at this time.
github.com/sigstore/policy-controller < 0.2.1Upgrade to a patched release:
github.com/sigstore/policy-controller 0.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-29902Medium· 4.2Cosign malicious attachments can cause system-wide denial of service
CVE-2026-44309Medium· 5.3gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
CVE-2026-44310Medium· 5.4gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
CVE-2026-22772Medium· 5.8Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
CVE-2025-66564High· 7.5Sigstore Timestamp Authority allocates excessive memory during request parsing
CVE-2023-30551High· 7.5Rekor's compressed archives can result in OOM conditions