Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-23649

17
FAUCET Score

CVE-2022-23649 is a low-severity vulnerability affecting sigstore Cosign versions prior to 1.5.2, allowing an attacker with push/pull OCI permissions to manipulate Cosign into falsely believing a signature entry exists in the Rekor transparency log. The attack vector is local with low complexity, resulting in a low impact on integrity (CVSS 3.3). There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. The issue has been patched in Cosign v1.5.2 by verifying the signature in the signedEntryTimestamp against the signature being verified.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.5.2CPE matchmatch criteria
cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 38th percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/sigstore/cosignFixed in: 1.5.2

Vendor Advisories (1)

goGHSA-ccxc-vr6p-4858low

Improper Certificate Validation in Cosign

Feb 22, 2022

References

github.com / sigstore/cosign/commit/96d410a6580e4e81d24d112a0855c70ca3fb5b49
PatchThird Party Advisory
github.com / sigstore/cosign/security/advisories/GHSA-ccxc-vr6p-4858
Third Party Advisory