
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39395 is a logic flaw in Cosign's verify-blob-attestation command that causes it to erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. It affects Sigstore Cosign versions prior to 2.6.3 (2.x branch) and versions 3.0.0 through 3.0.5 (3.x branch). The vulnerability was published on April 7, 2026, with patches released as versions 2.6.3 and 3.0.6. It carries a CVSS v3.1 base score of 4.3 (Moderate) (GitHub Advisory, Sigstore Advisory).
The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions). For old-format bundles and detached signatures, a logic flaw in the error handling of predicate type validation allows malformed or unparsable payloads to pass verification silently. For new-format bundles, predicate type validation is bypassed entirely. The vulnerability is specifically triggered when cosign verify-blob-attestation is invoked without --check-claims=true, allowing an attestation with a valid signature but a malformed or mismatched payload to be accepted as legitimate (GitHub Advisory, Sigstore Advisory).
Successful exploitation allows an attacker to craft attestations with malformed payloads or mismatched predicate types that falsely pass Cosign's verification checks, undermining software supply chain integrity. Systems relying on --type to enforce attestation type constraints would be deceived into trusting unexpected attestation types, potentially enabling the deployment of unauthorized or tampered container images and binaries. There is no confidentiality or availability impact; the risk is limited to integrity, specifically the trustworthiness of the attestation verification process (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.042% (13th percentile), indicating a low near-term exploitation probability. Exploitation requires user interaction (a user or automated pipeline must invoke verify-blob-attestation against a crafted attestation), limiting opportunistic attack scenarios (GitHub Advisory).
cosign verify-blob-attestation without the --check-claims=true flag.cosign verify-blob-attestation returning "Verified OK" for artifacts that were not expected to have valid attestations, or for attestation types inconsistent with the pipeline's policy.cosign verify-blob-attestation without the --check-claims=true flag in pipeline scripts or automation.Upgrade Cosign to version 2.6.3 (for the 2.x branch) or 3.0.6 (for the 3.x branch) to fully remediate the vulnerability. As an immediate workaround prior to upgrading, always invoke cosign verify-blob-attestation with --check-claims=true to enforce payload validation. Additionally, review any attestations previously verified with vulnerable Cosign versions to confirm their legitimacy, and consider implementing supplementary validation in supply chain workflows (GitHub Advisory, Sigstore Advisory).
The vulnerability was reported by researcher kodareef5 and published by Hayden-IO via the Sigstore/Cosign GitHub security advisory process on April 6, 2026. No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability database aggregation (Sigstore Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."