{"id":"DEBIAN-CVE-2026-39395","details":"Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a \"Verified OK\" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.","modified":"2026-09-29T11:02:42.330227962Z","published":"2026-04-07T20:16:33.140Z","upstream":["CVE-2026-39395"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-39395"}],"affected":[{"package":{"name":"cosign","ecosystem":"Debian:13","purl":"pkg:deb/debian/cosign?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5.0-2","2.6.2-1","2.6.2-1~exp0","2.6.3-1","3.0.5-1~exp0","3.0.6-1","3.0.6-1~exp0","3.1.0-1~exp0","3.1.1-1","3.1.1-1~exp0"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-39395.json"}},{"package":{"name":"cosign","ecosystem":"Debian:14","purl":"pkg:deb/debian/cosign?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.3-1"}]}],"versions":["2.5.0-2","2.6.2-1","2.6.2-1~exp0"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-39395.json"}}],"schema_version":"1.9.0"}