
CVE-2026-24122: Time Travelers & Zombie Chains: Deep Dive into CVE-2026-24122 in Sigstore Cosign A temporal logic flaw in Sigstore Cosign's certificate validation allowed expired intermediate Certificate Authorities to validate signatures if the leaf ... https://cvereports.com/reports/CVE-2026-24122
Post summary
The post announces CVE-2026-24122, noting a temporal logic flaw in Sigstore Cosign’s certificate validation that permits expired intermediate CAs to validate signatures, but it does not provide a PoC, exploit tool, active exploitation evidence, patch, or false‑positive claim.

