Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-36056

21
FAUCET Score

CVE-2022-36056 is a medium-severity vulnerability affecting sigstore cosign versions prior to 1.12.0, where multiple flaws in the verify-blob function could lead to successful verification of artifacts that should have failed. This could occur due to issues with crafted bundles, unchecked certificate identities, and invalid Rekor bundles or transparency log entries. The vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and local attack vector, with a potential impact of high integrity compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.12.0CPE matchmatch criteria
cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 26th percentile among its peer group of 15,937 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/sigstore/cosignFixed in: 1.12.0
redhatpatch availablevia redhat_api
Product: RHACS-3.73-RHEL-8Fixed in: advanced-cluster-security/rhacs-main-rhel8:3.73.0-4
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.73-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-rhel8:3.73.0-4
View patch
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: openshift-serverless-1/client-kn-rhel8

Vendor Advisories (2)

goGHSA-8gw7-4j42-w388medium

Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature

Sep 16, 2022
redhatCVE-2022-36056Low

app-containers/cosign: false positive verification

Sep 14, 2022

References

github.com / sigstore/cosign/commit/80b79ed8b4d28ccbce3d279fd273606b5cddcc25
PatchThird Party Advisory
github.com / sigstore/cosign/security/advisories/GHSA-8gw7-4j42-w388
ExploitMitigationPatchThird Party Advisory