Signatures considered valid with certificates that outlive expired CA certificates
Fixed in: cosign 3.0.5
patched
details
Finding IDs
F-COSIGN-001-003
CVE
CVE-2026-24122
GHSA
GHSA-wfqv-66vq-46rm
Status
patched
Fixed in
cosign 3.0.5
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE registry state
PUBLISHED
CVE state checked
Upstream title
Signatures considered valid with certificates that outlive expired CA certificates
Upstream CWE
CWE-295
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: reporter (accepted)
F-COSIGN-001-003: Verification failures. Certificate validation does not enforce the issuing CA validity boundary. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.