StackRadar

CVE-2026-24122

Low

Advisory

Published 19 Feb 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
20
deployed by those charts
Fix available
2 of 3
affected packages

Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 20 images.

Affected packageAffected versionsFixed inImages
github.com/sigstore/cosign/v2golangv2.1.1, v2.2.0, v2.2.4, v2.4.1+4 moreno fix listed13
github.com/sigstore/cosign/v3golangv3.0.43.0.51
github.com/sigstore/cosigngolangv1.8.0, v1.13.1, v1.13.63.0.56
OSV records
GHSA-wfqv-66vq-46rmGO-2026-4529
Also known as
BIT-cosign-2026-24122

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
harborharborOfficialVerified publisher1.19.21 of 8See more

harbor harbor 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
no fix listed

Open the chart page →

1,650
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/cosign/v2@v2.6.2
no fix listed
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/cosign/v2@v2.6.2
no fix listed

Open the chart page →

10,755
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
securesystemsengineering/connaisseur:v3.12.038918befbdad
github.com/sigstore/cosign/v2@v2.6.4
no fix listed

Open the chart page →

3,012
policy-controllersigstoreVerified publisher0.10.71 of 2See more

policy-controller sigstore 0.10.7

1 of the 2 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
github.com/sigstore/cosign/v2@v2.5.0
no fix listed

Open the chart page →

911
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/cosign/v2@v2.2.4
no fix listed

Open the chart page →

1,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.11 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/cosign/v2@v2.1.1
no fix listed

Open the chart page →

7,087
spirephilips-labsVerified publisher0.12.21 of 6See more

spire philips-labs 0.12.2

1 of the 6 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/sigstore/cosign@v1.13.1
3.0.5

Open the chart page →

7,236
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/sigstore/cosign/v2@v2.6.2
no fix listed

Open the chart page →

8,158
artifact-hubsoftonic1.19.03 of 8See more

artifact-hub softonic 1.19.0

3 of the 8 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
artifacthub/hub:v1.19.0111918d8c399
github.com/sigstore/cosign@v1.13.6
3.0.5
artifacthub/scanner:v1.19.0323d026e78c3
github.com/sigstore/cosign@v1.13.6
3.0.5
artifacthub/tracker:v1.19.06596c8c4d955
github.com/sigstore/cosign@v1.13.6
3.0.5

Open the chart page →

14,491
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/sigstore/cosign@v1.8.0
3.0.5
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/sigstore/cosign@v1.8.0
3.0.5

Open the chart page →

4,722
harborgpg-dev1.18.31 of 8See more

harbor gpg-dev 1.18.3

1 of the 8 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/cosign/v2@v2.6.2
no fix listed

Open the chart page →

3,376
harborhelm-harborVerified publisher2.3.51 of 8See more

harbor helm-harbor 2.3.5

1 of the 8 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
no fix listed

Open the chart page →

1,650
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/cosign/v2@v2.2.4
no fix listed

Open the chart page →

1,893
agent-control-cdnewrelic1.0.01 of 3See more

agent-control-cd newrelic 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/cosign/v2@v2.4.1
no fix listed

Open the chart page →

5,034
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/cosign/v2@v2.2.0
no fix listed

Open the chart page →

8,599
portagerportager0.5.01 of 1See more

portager portager 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/jarodr47/portager:0.5.06a7a61b37568
github.com/sigstore/cosign/v2@v2.6.5
no fix listed

Open the chart page →

137
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
github.com/sigstore/cosign/v3@v3.0.4
3.0.5

Open the chart page →

424
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-24122.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
no fix listed

Open the chart page →

1,650

Container images carrying it

20 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
no fix listed
3
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/cosign/v2@v2.6.2
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
github.com/sigstore/cosign@v1.13.6
3.0.5
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/cosign/v2@v2.6.2
no fix listed
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/sigstore/cosign@v1.13.6
3.0.5
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/sigstore/cosign@v1.13.6
3.0.5
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/cosign/v2@v2.1.1
no fix listed
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/cosign/v2@v2.6.2
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/sigstore/cosign/v2@v2.6.2
no fix listed
1
securesystemsengineering/connaisseur:v3.12.038918befbdad
github.com/sigstore/cosign/v2@v2.6.4
no fix listed
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/cosign/v2@v2.4.1
no fix listed
1
ghcr.io/jarodr47/portager:0.5.06a7a61b37568
github.com/sigstore/cosign/v2@v2.6.5
no fix listed
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/cosign/v2@v2.2.4
no fix listed
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/sigstore/cosign@v1.8.0
3.0.5
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/sigstore/cosign@v1.8.0
3.0.5
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/cosign/v2@v2.2.4
no fix listed
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
github.com/sigstore/cosign/v2@v2.5.0
no fix listed
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
github.com/sigstore/cosign/v3@v3.0.4
3.0.5
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/sigstore/cosign@v1.13.1
3.0.5
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/cosign/v2@v2.2.0
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.