🛡️ SUSE-SU-2026:20904-1 — cosign (CVE-2026-24122 +8 more)
Description
Security update for cosign
This update for cosign fixes the following issues:
Update to version 3.0.5:
- CVE-2026-24122: Fixed improper validation of certificates that outlive
expired CA certificates (bsc#1258542)
- CVE-2026-26958: Fixed filippo.io/edwards25519: failure to initialize receiver
in MultiScalarMult can produce invalid results and lead to undefined behavior
(bsc#1258612)
- CVE-2026-24137: Fixed github.com/sigstore/sigstore/pkg/tuf: legacy TUF client
allows for arbitrary file writes with target cache path traversal
(bsc#1257139)
- CVE-2026-22772: Fixed github.com/sigstore/fulcio: bypass MetaIssuer URL
validation bypass can trigger SSRF to arbitrary internal services
(bsc#1256562)
- CVE-2026-23991: Fixed github.com/theupdateframework/go-tuf/v2: denial of
service due to invalid TUF metadata JSON returned by TUF repository
(bsc#1257080)
- CVE-2026-23992: Fixed github.com/theupdateframework/go-tuf/v2: unauthorized
modification to TUF metadata files due to a compromised or misconfigured TUF
repository (bsc#1257085)
- CVE-2025-11065: Fixed github.com/go-viper/mapstructure/v2: sensitive
Information leak in logs (bsc#1250620)
- CVE-2026-22703: Fixed that cosign verification accepts any valid Rekor entry
under certain conditions (bsc#1256496)
- CVE-2025-58181: Fixed golang.org/x/crypto/ssh: invalidated number of
mechanisms can cause unbounded memory consumption (bsc#1253913)
Affected software
SUSE-SU-2026:20904-1 is recorded against 1 package.
- cosign (fixed in 3.0.5-160000.1.1)
Timeline and source
Published on 18 March 2026 and last revised on 2 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| cosign | — | 3.0.5-160000.1.1 |
References
Similar Threats
- Unknown CGA-2mv5-7p9w-vp27
- Unknown CGA-3w5r-2f79-3p9x
- Unknown CGA-33qc-7m28-fvwr
- Unknown CGA-37xx-2fqv-rjhr
- Unknown CGA-382c-27vm-3c8m
Free Vulnerability Check
Is your site affected by SUSE-SU-2026:20904-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:20904-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.