Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39395

21
FAUCET Score

OVERVIEW CVE-2026-39395 is a verification bypass vulnerability in Cosign, a container and binary code signing tool. The flaw affects versions prior to 3.0.6 and 2.6.3, allowing the verify-blob-attestation function to incorrectly report successful verification for attestations with malformed payloads or mismatched predicate types. The vulnerability stems from logic flaws in predicate type validation for legacy bundle formats and complete validation bypass in newer bundle formats. SEVERITY This vulnerability carries a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, meaning an attacker can exploit this flaw with relative ease. The primary impact is integrity-focused: an attacker could distribute falsely verified attestations, potentially allowing malicious code to be trusted as legitimate. No confidentiality or availability impacts are expected. EXPLOITATION STATUS The vulnerability is not currently being actively exploited in the wild. No known exploit code is publicly available, and the CVE has not appeared on CISA's Known Exploited Vulnerabilities list. Community attention remains minimal, reflected in the low EPSS score of 0.00038, indicating this vulnerability represents a lower exploitation probability compared to other disclosed CVEs. Organizations should update to the patched versions when feasible, but this is not an urgent critical threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.6.3CPE matchmatch criteria
cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.6CPE matchmatch criteria
cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 6th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

gopatch availablevia ghsa
Product: github.com/sigstore/cosignFixed in: 3.0.6
gopatch availablevia ghsa
Product: github.com/sigstore/cosignFixed in: 2.6.3
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-w6c6-c85g-mmv6medium

Cosign's verify-blob-attestation reports false positive when payload parsing fails

Apr 8, 2026

References

github.com / sigstore/cosign/security/advisories/GHSA-w6c6-c85g-mmv6
MitigationVendor Advisory