Sigstore is a modestly represented vendor in the landscape providing cryptographic signing and verification tools for software supply-chain security, with a focused product line centered on signing utilities such as Cosign and Gitsign alongside policy enforcement and Go-native implementations. Its vulnerability profile recurs through weakness classes reflecting the vendor's cryptographic and verification mandate: improper signature verification, certificate validation issues, and resource-exhaustion conditions such as infinite loops and unreachable exit paths that can arise in parsing and validation logic. Defenders tracking software provenance and container signing should monitor this vendor's releases for authentication and verification correctness, as flaws in the signing and policy layers underpin the integrity of downstream artifact validation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sigstore over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35929CRITICAL cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used w | Aug 4, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-35930HIGH PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a false positive, resulting in an | Aug 4, 2022 | 8.8 | 27 | NO | NO |
CVE-2026-31830HIGH sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verify does not propagate the Verifi | Mar 10, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-39395MEDIUM Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result fo | Apr 7, 2026 | 5.3 | 21 | NO | NO |
CVE-2026-22703MEDIUM Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even i | Jan 10, 2026 | 5.5 | 21 | NO | NO |
CVE-2024-29903HIGH Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause denial of service of the machine | Apr 10, 2024 | 7.5 | 21 | NO | NO |
CVE-2022-36056MEDIUM Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found | Sep 14, 2022 | 5.5 | 21 | NO | NO |
CVE-2024-45395HIGH sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier is provided a maliciously c | Sep 4, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-29902MEDIUM Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cause denial of service of the hos | Apr 10, 2024 | 5.9 | 18 | NO | NO |
CVE-2023-47122MEDIUM Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead | Nov 10, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sigstore.
Media articles that mention a CVE ID that affects a product developed by Sigstore — matched by CVE ID, not by vendor name.