« Volver al listado

CVE-2026-39395

Estado: AnalizadaMedia (5.3)—

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-39395",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-39395",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-08T15:49:08.895545Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "sigstore",
          "product": "cosign",
          "versions": [
            {
              "status": "affected",
              "version": ">= 3.0.0, < 3.0.6"
            },
            {
              "status": "affected",
              "version": "< 2.6.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-07T20:16:33.140",
  "references": [
    {
      "url": "https://github.com/sigstore/cosign/security/advisories/GHSA-w6c6-c85g-mmv6",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-754"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a \"Verified OK\" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3."
    },
    {
      "lang": "es",
      "value": "Cosign proporciona firma de código y transparencia para contenedores y binarios. Antes de 3.0.6 y 2.6.3, cosign verify-blob-attestation podría informar erróneamente un resultado de 'Verified OK' para atestaciones con cargas útiles malformadas o tipos de predicado no coincidentes. Para paquetes de formato antiguo y firmas separadas, esto se debía a un fallo lógico en el manejo de errores de la validación del tipo de predicado. Para paquetes de formato nuevo, la validación del tipo de predicado fue omitida por completo. Esta vulnerabilidad está corregida en 3.0.6 y 2.6.3."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1C20B41-D20F-4FC4-AFD6-00C45B60CC58",
              "versionEndExcluding": "2.6.3"
            },
            {
              "criteria": "cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DD2B507-E86E-4276-86EC-0FDE82CB0BB1",
              "versionEndExcluding": "3.0.6",
              "versionStartIncluding": "3.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}