{"api_version":"v1","generated_at":"2026-10-08T10:40:00+00:00","product":{"cve_count":9,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-sigstore-cosign-dd2c7c419f1e","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cosign","name":"cosign","next_cursor":null,"observations":[{"affected":">= 3.0.0, < 3.0.6; < 2.6.3","affected_versions_present":true,"cve_id":"CVE-2026-39395","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39395","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T15:49:16.587Z","patch_url":"https://github.com/sigstore/cosign/security/advisories/GHSA-w6c6-c85g-mmv6","primary_source":"","published":"2026-04-07T20:06:28.798Z"},{"affected":"< 3.0.5","affected_versions_present":true,"cve_id":"CVE-2026-24122","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24122","fixed":"3.0.5.","last_modified":"2026-02-20T15:41:03.939Z","patch_url":"https://github.com/sigstore/cosign/commit/3c9a7363f563db76d78e2de2cabd945450f3781e","primary_source":"","published":"2026-02-19T22:27:08.828Z"},{"affected":"< 3.0.4; < 2.6.2","affected_versions_present":true,"cve_id":"CVE-2026-22703","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22703","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-12T16:43:57.302Z","patch_url":"https://github.com/sigstore/cosign/commit/6832fba4928c1ad69400235bbc41212de5006176","primary_source":"","published":"2026-01-10T06:11:09.426Z"},{"affected":"< 2.2.4","affected_versions_present":true,"cve_id":"CVE-2024-29903","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29903","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T01:17:58.600Z","patch_url":"https://github.com/sigstore/cosign/commit/629f5f8fa672973503edde75f84dcd984637629e","primary_source":"","published":"2024-04-10T22:30:50.890Z"},{"affected":"< 2.2.4","affected_versions_present":true,"cve_id":"CVE-2024-29902","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29902","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T01:17:58.609Z","patch_url":"https://github.com/sigstore/cosign/commit/629f5f8fa672973503edde75f84dcd984637629e","primary_source":"","published":"2024-04-10T22:28:19.788Z"},{"affected":"< 2.2.1","affected_versions_present":true,"cve_id":"CVE-2023-46737","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-46737","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-04T15:23:23.311Z","patch_url":"https://github.com/sigstore/cosign/commit/8ac891ff0e29ddc67965423bee8f826219c6eb0f","primary_source":"","published":"2023-11-07T17:30:25.717Z"},{"affected":"< 1.12.0","affected_versions_present":true,"cve_id":"CVE-2022-36056","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36056","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-22T17:21:40.980Z","patch_url":"https://github.com/sigstore/cosign/security/advisories/GHSA-8gw7-4j42-w388","primary_source":"","published":"2022-09-14T19:50:09.000Z"},{"affected":"< 1.10.1","affected_versions_present":true,"cve_id":"CVE-2022-35929","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-35929","fixed":"1.10.1","last_modified":"2025-04-22T17:43:02.289Z","patch_url":"https://github.com/sigstore/cosign/commit/c5fda01a8ff33ca981f45a9f13e7fb6bd2080b94","primary_source":"","published":"2022-08-04T18:45:14.000Z"},{"affected":"< 1.5.2","affected_versions_present":true,"cve_id":"CVE-2022-23649","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23649","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:02:31.515Z","patch_url":"https://github.com/sigstore/cosign/commit/96d410a6580e4e81d24d112a0855c70ca3fb5b49","primary_source":"","published":"2022-02-18T21:30:10.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"sigstore"}}
