CVE-2026-24122Disclosure(sigstore / cosign)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification even if the provided timestamp would mean the issuing certificate should be considered expired. When verifying artifact signatures using a certificate, Cosign first verifies the certificate chain using the leaf certificate's "not before" timestamp and later checks expiry of the leaf certificate using either a signed timestamp provided by the Rekor transparency log or from a timestamp authority, or using the current time. The root and all issuing certificates are assumed to be valid during the leaf certificate's validity. There is no impact to users of the public Sigstore infrastructure. This may affect private deployments with customized PKIs. This issue has been fixed in version 3.0.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cosign

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cosign

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 102-1902-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24122: Time Travelers & Zombie Chains: Deep Dive into CVE-2026-24122 in Sigstore Cosign A temporal logic flaw in Sigstore Cosign's certificate validation allowed expired intermediate Certificate Authorities to validate signatures if the leaf ... https://cvereports.com/reports/CVE-2026-24122

    Post summary

    The post announces CVE-2026-24122, noting a temporal logic flaw in Sigstore Cosign’s certificate validation that permits expired intermediate CAs to validate signatures, but it does not provide a PoC, exploit tool, active exploitation evidence, patch, or false‑positive claim.

    0000145
    26 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24122 Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the… https://www.cve.org/CVERecord?id=CVE-2026-24122

    Post summary

    The post discloses CVE-2026-24122 affecting Cosign <=3.0.4, indicating a certificate validity issue, with no evidence of exploits, patches, or active attacks.

    00000132
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsigstorecosign---

Explore more