
CVE-2026-39395 Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified… https://www.cve.org/CVERecord?id=CVE-2026-39395
Post summary
The notice indicates that cosign verify-blob-attestation might incorrectly report a result for CVE-2026-39395, suggesting the vulnerability may be a false positive, with no patch or technical details provided.
