CVE-2026-39395: Cosign's verify-blob-attestation reports false positive when payload parsing fails
Description
cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely.
Impact
When cosign verify-blob-attestation is used without --check-claims set to true, an attestation that has a valid signature but a malformed or unparsable payload would be incorrectly validated. Additionally, systems relying on --type <predicate type> to reject attestations with mismatched types would be lead to trust the unexpected attestation type.
Patches
v3.0.6, v2.6.3
Workarounds
Always set --check-claims=true for attestation verification.
Other sources
Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/sigstore/cosignto a version that resolves this vulnerability.Fixed in 2.6.3 - Upgrade
Upgrade
go/github.com/sigstore/cosignto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
cosignto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
cosignto a version that resolves this vulnerability.Fixed in 2.6.3 - Configuration
Always set --check-claims=true for attestation verification.
cosign verify-blob-attestation --check-claims = true