Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sigstore

First CVE: Feb 18, 2022Active for: 4 yearsTotal CVEs: 13
23.1
VTI Score
Low

Sigstore is a modestly represented vendor in the landscape providing cryptographic signing and verification tools for software supply-chain security, with a focused product line centered on signing utilities such as Cosign and Gitsign alongside policy enforcement and Go-native implementations. Its vulnerability profile recurs through weakness classes reflecting the vendor's cryptographic and verification mandate: improper signature verification, certificate validation issues, and resource-exhaustion conditions such as infinite loops and unreachable exit paths that can arise in parsing and validation logic. Defenders tracking software provenance and container signing should monitor this vendor's releases for authentication and verification correctness, as flaws in the signing and policy layers underpin the integrity of downstream artifact validation; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sigstore over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2022
4 years ago
Most Recent CVE
Apr 7, 2026
109 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-35929CRITICAL
cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used w
Aug 4, 20229.831NONO
CVE-2022-35930HIGH
PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a false positive, resulting in an
Aug 4, 20228.827NONO
CVE-2026-31830HIGH
sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verify does not propagate the Verifi
Mar 10, 20267.524NONO
CVE-2026-39395MEDIUM
Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result fo
Apr 7, 20265.321NONO
CVE-2026-22703MEDIUM
Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even i
Jan 10, 20265.521NONO
CVE-2024-29903HIGH
Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause denial of service of the machine
Apr 10, 20247.521NONO
CVE-2022-36056MEDIUM
Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found
Sep 14, 20225.521NONO
CVE-2024-45395HIGH
sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier is provided a maliciously c
Sep 4, 20247.520NONO
CVE-2024-29902MEDIUM
Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cause denial of service of the hos
Apr 10, 20245.918NONO
CVE-2023-47122MEDIUM
Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead
Nov 10, 20235.318NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
15%
46%
31%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (23.1%)
Network10 (76.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High3 (23.1%)
Unknown0 (0.0%)
User Interaction
None12 (92.3%)
Unknown0 (0.0%)
Required1 (7.7%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None9 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sigstore.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sigstore — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sigstore's Products

View all 1 CNAs →

Top CWEs