remote crash in policy evaluation via unsafe attestation payload type assertion
merged
details
Finding IDs
F-COSIGN-006
Status
merged
Reported date
Rationale
prevents remote crash via malformed attestation payloads.
PR opened by
@1seal
PR state observed
closed; GitHub merged: true; 2026-09-24
PR observation basis
Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
Contribution boundary
@1seal opened this PR; this alone does not establish sole code authorship.
F-COSIGN-006: Input / state handling. Malformed attestation input reaches an unchecked type assertion. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.