github.com/sigstore/cosign/v2 vulnerabilities
CVEs whose affected-version data names the github.com/sigstore/cosign/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-22703Medium· 5.5Cosign verification accepts any valid Rekor entry under certain conditions
Cosign verification accepts any valid Rekor entry under certain conditions
▾ Sunlitsigstore · github.com/sigstore/cosign/v3EPSS 0.10%via OSV
CVE-2024-29902Medium· 4.2Cosign malicious attachments can cause system-wide denial of service
Cosign malicious attachments can cause system-wide denial of service
▾ Sunlitsigstore · github.com/sigstore/cosignEPSS 0.66%via OSV