GPU VulnDB

Database/Container, Kubernetes & orchestration

cosign / sigstore: A crafted bundle verifies successfully even though the embedded Rekor entry does not reference

CVE-2026-22703Container, Kubernetes & orchestrationcurated

Impact

A crafted bundle verifies successfully even though the embedded Rekor entry does not reference the artifact; signature policy bypass

Who can reach it

Malicious image

What to do

Upgrade cosign to 2.6.2/3.0.4+; re-verify admitted images

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.