Improper Certificate Validation in Cosign - CVE-2026-24122
Published: April 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass signature verification integrity checks.
The vulnerability exists due to improper certificate validation in certificate chain verification when verifying artifact signatures using certificates with signed timestamps. A remote attacker can present a certificate chain in which an issuing certificate expires before the leaf certificate to bypass signature verification integrity checks.
This affects private deployments with customized PKIs and is unlikely to occur in practice because certification authorities should not issue certificates that outlive the validity of their issuing certificates.
Affected software
Anolis OS
cosign
How to mitigate CVE-2026-24122
cosign - update to 2.5.2-3