VDB
GO-2026-4529
GO-2026-4529
PUBLISHED
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wolfi | kyverno-notation-aws | 0, 0, 0 |
| chainguard | ratify-fips | 0, 0, 0 |
| chainguard | trivy-operator | 0, 0, 0 |
| chainguard | commercial-chainloop-backend | 0, 0, 0 |
| chainguard | skaffold-fips | 0, 0, 0 |
| chainguard | crossplane-1.20 | 0, 0, 0 |
| chainguard | kyverno-fips-1.14 | 0, 0, 0 |
| wolfi | zot | 0, 0, 0 |
| chainguard | crossplane-fips-2.0 | 0, 0, 0 |
| chainguard | kyverno-fips-1.16 | 0, 0, 0 |
| wolfi | aactl | 0, 0, 0 |
| chainguard | trivy-fips | 0, 0, 0 |
| chainguard | kyverno-notation-aws-fips | 0, 0, 0 |
| chainguard | cloudbeat-9.3 | 0, 0, 0 |
| wolfi | kyverno-1.16 | 0, 0, 0 |
| wolfi | kyverno-1.17 | 0, 0, 0 |
| chainguard | cloudbeat-fips-9.4 | 0, 0, 0 |
| chainguard | kyverno-fips-1.17 | 0, 0, 0 |
| chainguard | security-profiles-operator | 0, 0 |
| chainguard | commercial-kyverno-1.17 | 0, 0, 0 |
…and 62 more
Timeline
- Feb 23, 2026 CVE Published
- Jun 16, 2026 CVE Updated
- Sep 1, 2026 Security Advisory