OVERVIEW CVE-2026-39395 is a verification bypass vulnerability in Cosign, a container and binary code signing tool. The flaw affects versions prior to 3.0.6 and 2.6.3, allowing the verify-blob-attestation function to incorrectly report successful verification for attestations with malformed payloads or mismatched predicate types. The vulnerability stems from logic flaws in predicate type validation for legacy bundle formats and complete validation bypass in newer bundle formats. SEVERITY This vulnerability carries a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, meaning an attacker can exploit this flaw with relative ease. The primary impact is integrity-focused: an attacker could distribute falsely verified attestations, potentially allowing malicious code to be trusted as legitimate. No confidentiality or availability impacts are expected. EXPLOITATION STATUS The vulnerability is not currently being actively exploited in the wild. No known exploit code is publicly available, and the CVE has not appeared on CISA's Known Exploited Vulnerabilities list. Community attention remains minimal, reflected in the low EPSS score of 0.00038, indicating this vulnerability represents a lower exploitation probability compared to other disclosed CVEs. Organizations should update to the patched versions when feasible, but this is not an urgent critical threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.3CPE matchmatch criteria | cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.6CPE matchmatch criteria | cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.