<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T10:27:56.899207+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-cosign-2022-36056</id>
    <title>BIT-cosign-2022-36056 — Vulnerabilities with blob verification in sigstore cosign</title>
    <updated>2026-10-05T10:27:56.905209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: cosign</p>
<p>Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should have failed. First a cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature. Second, when providing identity flags, the email and issuer of a certificate is not checked when verifying a Rekor bundle, and the GitHub Actions identity is never checked. Third, providing an invalid Rekor bundle without the experimental flag results in a successful verification. And fourth an invalid transparency log entry will result in immediate success for verification. Details and examples of these issues can be seen in the GHSA-8gw7-4j42-w388 advisory linked. Users are advised to upgrade to 1.12.0. There are no known workarounds for these issues.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-cosign-2022-36056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</id>
    <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-05T10:27:56.905286+00:00</updated>
    <content>certfr-2025-avi-0622</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-oh46796</id>
    <title>CLEANSTART-2026-OH46796 — Security fix for CVE-2022-36056 applied in: cosign 1.12.1-r0</title>
    <updated>2026-10-05T10:27:56.905316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: cosign</p>
<p>Security vulnerability affects the cosign package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-oh46796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232616</id>
    <title>EUVD-2026-232616</title>
    <updated>2026-10-05T10:27:56.905349+00:00</updated>
    <content>EUVD-2026-232616</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36056</id>
    <title>fkie_cve-2022-36056</title>
    <updated>2026-10-05T10:27:56.905377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should have failed. First a cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature. Second, when providing identity flags, the email and issuer of a certificate is not checked when verifying a Rekor bundle, and the GitHub Actions identity is never checked. Third, providing an invalid Rekor bundle without the experimental flag results in a successful verification. And fourth an invalid transparency log entry will result in immediate success for verification. Details and examples of these issues can be seen in the GHSA-8gw7-4j42-w388 advisory linked. Users are advised to upgrade to 1.12.0. There are no known workarounds for these issues.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8gw7-4j42-w388</id>
    <title>GHSA-8gw7-4j42-w388 — Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the give…</title>
    <updated>2026-10-05T10:27:56.905405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/sigstore/cosign</p>
<p>## Summary</p>
<p>A number of vulnerabilities have been found in `cosign verify-blob`, where Cosign would successfully verify an artifact when verification should have failed.</p>
<p>## Vulnerability 1: Bundle mismatch causes invalid verification.</p>
<p>### Summary
A cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature.</p>
<p>### Details
Cosign supports "bundles" which intend to allow offline verification of the signature and rekor inclusion. By using the --bundle flag in cosign sign-blob, cosign will create a JSON file called a "bundle". These bundles include three fields: base64Signature, cert, and rekorBundle. The desired behavior is that the verification of these bundles would:</p>
<p>- verify the provided blob using the included signature and certificate
- verify the rekorBundle SET
- verify the rekorBundle payload references the given artifact.</p>
<p>It appears that step three is not being performed, allowing "any old rekorBundle" to pass validation, even if the rekorBundle payload does not reference the provided blob or the certificate and signature in the rekorBundle do not match those at the top level.</p>
<p>### Steps to reproduce
Enable keyless signing:</p>
<p>```
export COSIGN_EXPERIMENTAL=1
```
Create two random blobs:
```
dd bs=1 count=50 &lt;/dev/urandom &gt;blob1
dd bs=1 count=50 &lt;/dev/urandom &gt;blob2
```
Sign each blob:
```
cosign sign-blob blob1 --bundle bundle1
cosign sign-blob blob2 --bundle bundle2
```
Create a falsified bundle…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8gw7-4j42-w388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36056</id>
    <title>gsd-2022-36056</title>
    <updated>2026-10-05T10:27:56.905460+00:00</updated>
    <content>gsd-2022-36056</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12331-1</id>
    <title>openSUSE-SU-2024:12331-1 — cosign-1.12.0-1.1 on GA media</title>
    <updated>2026-10-05T10:27:56.905473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cosign-1.12.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12331-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:8827</id>
    <title>RHSA-2022:8827 — Red Hat Security Advisory: RHACS 3.73 enhancement and security update</title>
    <updated>2026-10-05T10:27:56.905489+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path app-containers/cosign: false positive verification</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:8827"/>
  </entry>
</feed>
