CVE-2026-39395
Datadog Agent vulnerability analysis and mitigation

Overview

CVE-2026-39395 is a logic flaw in Cosign's verify-blob-attestation command that causes it to erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. It affects Sigstore Cosign versions prior to 2.6.3 (2.x branch) and versions 3.0.0 through 3.0.5 (3.x branch). The vulnerability was published on April 7, 2026, with patches released as versions 2.6.3 and 3.0.6. It carries a CVSS v3.1 base score of 4.3 (Moderate) (GitHub Advisory, Sigstore Advisory).

Technical details

The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions). For old-format bundles and detached signatures, a logic flaw in the error handling of predicate type validation allows malformed or unparsable payloads to pass verification silently. For new-format bundles, predicate type validation is bypassed entirely. The vulnerability is specifically triggered when cosign verify-blob-attestation is invoked without --check-claims=true, allowing an attestation with a valid signature but a malformed or mismatched payload to be accepted as legitimate (GitHub Advisory, Sigstore Advisory).

Impact

Successful exploitation allows an attacker to craft attestations with malformed payloads or mismatched predicate types that falsely pass Cosign's verification checks, undermining software supply chain integrity. Systems relying on --type to enforce attestation type constraints would be deceived into trusting unexpected attestation types, potentially enabling the deployment of unauthorized or tampered container images and binaries. There is no confidentiality or availability impact; the risk is limited to integrity, specifically the trustworthiness of the attestation verification process (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.042% (13th percentile), indicating a low near-term exploitation probability. Exploitation requires user interaction (a user or automated pipeline must invoke verify-blob-attestation against a crafted attestation), limiting opportunistic attack scenarios (GitHub Advisory).

Exploitation steps

  1. Craft a malicious attestation: Create an attestation bundle with a valid cryptographic signature but a malformed, unparsable payload or a predicate type that does not match the expected type (e.g., substitute a SLSA provenance predicate with a different type).
  2. Target a vulnerable Cosign deployment: Identify a CI/CD pipeline or verification workflow using Cosign versions prior to 2.6.3 or 3.0.0–3.0.5 that invokes cosign verify-blob-attestation without the --check-claims=true flag.
  3. Deliver the crafted attestation: Supply the malformed attestation bundle to the verification step, either by compromising an artifact registry, intercepting the artifact delivery, or substituting the attestation file in the pipeline.
  4. Bypass verification: The vulnerable Cosign instance processes the attestation, fails to properly validate the predicate type or payload, and returns "Verified OK" — causing the pipeline to accept and potentially deploy the tampered or unauthorized artifact (GitHub Advisory, Sigstore Advisory).

Indicators of compromise

  • Logs: CI/CD pipeline logs showing cosign verify-blob-attestation returning "Verified OK" for artifacts that were not expected to have valid attestations, or for attestation types inconsistent with the pipeline's policy.
  • Process/Command: Invocations of cosign verify-blob-attestation without the --check-claims=true flag in pipeline scripts or automation.
  • File System: Presence of attestation bundle files with malformed JSON payloads or predicate type fields that do not match the declared type in the bundle metadata.
  • Network: Unexpected or anomalous attestation bundles fetched from artifact registries for images or blobs that should not have attestations (GitHub Advisory).

Mitigation and workarounds

Upgrade Cosign to version 2.6.3 (for the 2.x branch) or 3.0.6 (for the 3.x branch) to fully remediate the vulnerability. As an immediate workaround prior to upgrading, always invoke cosign verify-blob-attestation with --check-claims=true to enforce payload validation. Additionally, review any attestations previously verified with vulnerable Cosign versions to confirm their legitimacy, and consider implementing supplementary validation in supply chain workflows (GitHub Advisory, Sigstore Advisory).

Community reactions

The vulnerability was reported by researcher kodareef5 and published by Hayden-IO via the Sigstore/Cosign GitHub security advisory process on April 6, 2026. No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability database aggregation (Sigstore Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

cosign: 2.6.3-1

Fixed

trixie

cosign

Affected

Ubuntu

Unknown

devel

cosign

Unknown

resolute

cosign

Unknown

resolute (esm-apps)

cosign

Unknown

RHEL / CentOS

Unknown

Alpine

Fixed

edge

cosign: 3.0.6-r0

Fixed

v3.23

cosign: 2.6.3-r0

Fixed

SourceThis report was generated using AI

Related Datadog Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48702HIGH7.5
  • Datadog Agent logoDatadog Agent
  • neuvector-sigstore-interface
NoYesAug 13, 2026
CVE-2026-71556HIGH7.1
  • Packer logoPacker
  • kargo-1.8
NoYesAug 07, 2026
CVE-2026-71557MEDIUM6.3
  • Packer logoPacker
  • kyverno-fips-1.17
NoYesAug 07, 2026
CVE-2026-61711MEDIUM5.3
  • Docker logoDocker
  • podman-fips-6.0
NoYesAug 19, 2026
CVE-2026-61712LOW2.3
  • Docker logoDocker
  • kubescape-ksserver
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management