<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:27:48 +0000</lastBuildDate>
    <item>
      <title>BIT-cosign-2022-36056 — Vulnerabilities with blob verification in sigstore cosign</title>
      <link>https://cve.radiocsirt.org/vuln/bit-cosign-2022-36056</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cosign&lt;/p&gt;
&lt;p&gt;Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should have failed. First a cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature. Second, when providing identity flags, the email and issuer of a certificate is not checked when verifying a Rekor bundle, and the GitHub Actions identity is never checked. Third, providing an invalid Rekor bundle without the experimental flag results in a successful verification. And fourth an invalid transparency log entry will result in immediate success for verification. Details and examples of these issues can be seen in the GHSA-8gw7-4j42-w388 advisory linked. Users are advised to upgrade to 1.12.0. There are no known workarounds for these issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cosign&lt;/p&gt;
&lt;p&gt;Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should have failed. First a cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature. Second, when providing identity flags, the email and issuer of a certificate is not checked when verifying a Rekor bundle, and the GitHub Actions identity is never checked. Third, providing an invalid Rekor bundle without the experimental flag results in a successful verification. And fourth an invalid transparency log entry will result in immediate success for verification. Details and examples of these issues can be seen in the GHSA-8gw7-4j42-w388 advisory linked. Users are advised to upgrade to 1.12.0. There are no known workarounds for these issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-cosign-2022-36056</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-OH46796 — Security fix for CVE-2022-36056 applied in: cosign 1.12.1-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-oh46796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cosign package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cosign package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-oh46796</guid>
    </item>
    <item>
      <title>EUVD-2026-232616</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232616</link>
      <description>EUVD-2026-232616</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232616</guid>
    </item>
    <item>
      <title>fkie_cve-2022-36056</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36056</link>
      <description>&lt;p&gt;Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should have failed. First a cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature. Second, when providing identity flags, the email and issuer of a certificate is not checked when verifying a Rekor bundle, and the GitHub Actions identity is never checked. Third, providing an invalid Rekor bundle without the experimental flag results in a successful verification. And fourth an invalid transparency log entry will result in immediate success for verification. Details and examples of these issues can be seen in the GHSA-8gw7-4j42-w388 advisory linked. Users are advised to upgrade to 1.12.0. There are no known workarounds for these issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should have failed. First a cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature. Second, when providing identity flags, the email and issuer of a certificate is not checked when verifying a Rekor bundle, and the GitHub Actions identity is never checked. Third, providing an invalid Rekor bundle without the experimental flag results in a successful verification. And fourth an invalid transparency log entry will result in immediate success for verification. Details and examples of these issues can be seen in the GHSA-8gw7-4j42-w388 advisory linked. Users are advised to upgrade to 1.12.0. There are no known workarounds for these issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-36056</guid>
    </item>
    <item>
      <title>GHSA-8gw7-4j42-w388 — Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the give…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8gw7-4j42-w388</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sigstore/cosign&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A number of vulnerabilities have been found in `cosign verify-blob`, where Cosign would successfully verify an artifact when verification should have failed.&lt;/p&gt;
&lt;p&gt;## Vulnerability 1: Bundle mismatch causes invalid verification.&lt;/p&gt;
&lt;p&gt;### Summary
A cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature.&lt;/p&gt;
&lt;p&gt;### Details
Cosign supports &amp;#34;bundles&amp;#34; which intend to allow offline verification of the signature and rekor inclusion. By using the --bundle flag in cosign sign-blob, cosign will create a JSON file called a &amp;#34;bundle&amp;#34;. These bundles include three fields: base64Signature, cert, and rekorBundle. The desired behavior is that the verification of these bundles would:&lt;/p&gt;
&lt;p&gt;- verify the provided blob using the included signature and certificate
- verify the rekorBundle SET
- verify the rekorBundle payload references the given artifact.&lt;/p&gt;
&lt;p&gt;It appears that step three is not being performed, allowing &amp;#34;any old rekorBundle&amp;#34; to pass validation, even if the rekorBundle payload does not reference the provided blob or the certificate and signature in the rekorBundle do not match those at the top level.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce
Enable keyless signing:&lt;/p&gt;
&lt;p&gt;```
export COSIGN_EXPERIMENTAL=1
```
Create two random blobs:
```
dd bs=1 count=50 &amp;lt;/dev/urandom &amp;gt;blob1
dd bs=1 count=50 &amp;lt;/dev/urandom &amp;gt;blob2
```
Sign each blob:
```
cosign sign-blob blob1 --bundle bundle1
cosign sign-blob blob2 --bundle bundle2
```
Create a falsified bundle…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sigstore/cosign&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A number of vulnerabilities have been found in `cosign verify-blob`, where Cosign would successfully verify an artifact when verification should have failed.&lt;/p&gt;
&lt;p&gt;## Vulnerability 1: Bundle mismatch causes invalid verification.&lt;/p&gt;
&lt;p&gt;### Summary
A cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature.&lt;/p&gt;
&lt;p&gt;### Details
Cosign supports &amp;#34;bundles&amp;#34; which intend to allow offline verification of the signature and rekor inclusion. By using the --bundle flag in cosign sign-blob, cosign will create a JSON file called a &amp;#34;bundle&amp;#34;. These bundles include three fields: base64Signature, cert, and rekorBundle. The desired behavior is that the verification of these bundles would:&lt;/p&gt;
&lt;p&gt;- verify the provided blob using the included signature and certificate
- verify the rekorBundle SET
- verify the rekorBundle payload references the given artifact.&lt;/p&gt;
&lt;p&gt;It appears that step three is not being performed, allowing &amp;#34;any old rekorBundle&amp;#34; to pass validation, even if the rekorBundle payload does not reference the provided blob or the certificate and signature in the rekorBundle do not match those at the top level.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce
Enable keyless signing:&lt;/p&gt;
&lt;p&gt;```
export COSIGN_EXPERIMENTAL=1
```
Create two random blobs:
```
dd bs=1 count=50 &amp;lt;/dev/urandom &amp;gt;blob1
dd bs=1 count=50 &amp;lt;/dev/urandom &amp;gt;blob2
```
Sign each blob:
```
cosign sign-blob blob1 --bundle bundle1
cosign sign-blob blob2 --bundle bundle2
```
Create a falsified bundle…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8gw7-4j42-w388</guid>
    </item>
    <item>
      <title>gsd-2022-36056</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-36056</link>
      <description>gsd-2022-36056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-36056</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12331-1 — cosign-1.12.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12331-1</link>
      <description>&lt;p&gt;cosign-1.12.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cosign-1.12.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12331-1</guid>
    </item>
    <item>
      <title>RHSA-2022:8827 — Red Hat Security Advisory: RHACS 3.73 enhancement and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:8827</link>
      <description>&lt;p&gt;imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path app-containers/cosign: false positive verification&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path app-containers/cosign: false positive verification&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:8827</guid>
    </item>
  </channel>
</rss>
