Executive brief
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign
Affected products
- Go github.com/sigstore/cosign
- Go github.com/sigstore/cosign/v2
- Go github.com/sigstore/cosign/v3
Junglewise Threat Intelligence
CVE-2026-22703 · Severity: low · CVSS 3.1 · Published 2026-01-13
Technologies: github.com/sigstore/cosign (Go), github.com/sigstore/cosign/v2 (Go), github.com/sigstore/cosign/v3 (Go). Vendors: Go.
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign